{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3c5fc8e5-99ea-4d64-883d-ce253648b4ae",
  "version": 1,
  "metadata": {
    "timestamp": "2026-10-09T15:06:13+00:00",
    "tools": {
      "components": [
        {
          "type": "application",
          "manufacturer": {
            "name": "Aqua Security Software Ltd."
          },
          "group": "aquasecurity",
          "name": "trivy",
          "version": "0.69.3"
        }
      ]
    },
    "component": {
      "bom-ref": "ef915bc8-fb1c-4ca7-a6e1-bcecfe5f2652",
      "type": "application",
      "supplier": {
        "name": "Confluent"
      },
      "name": "confluent-ce-kafka-http-server",
      "version": "8.1.6-1",
      "properties": [
        {
          "name": "aquasecurity:trivy:SchemaVersion",
          "value": "2"
        }
      ]
    }
  },
  "components": [],
  "dependencies": [],
  "vulnerabilities": [
    {
      "id": "CVE-2026-106449",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        674
      ],
      "description": "yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to false handles each well-formed empty LZ4Block by recursively calling refill(), allowing a long sequence of empty blocks in an attacker-controlled compressed stream to exhaust the decoding thread's stack and throw StackOverflowError. The default stopOnEmptyBlock setting is true and is not affected, and the issue does not cause memory corruption. This issue is fixed in version 1.11.4.",
      "recommendation": "Upgrade at.yawk.lz4:lz4-java to version 1.11.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-106449"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-106449"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-106449"
        },
        {
          "url": "https://github.com/advisories/GHSA-343h-94h5-c4wr"
        },
        {
          "url": "https://github.com/yawkat/lz4-java"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/commit/c8ebf97d504fb34434fda46fc761e8202570e0d8"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/security/advisories/GHSA-343h-94h5-c4wr"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-106449"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-106449"
        }
      ],
      "published": "2026-10-06T20:17:26+00:00",
      "updated": "2026-10-07T17:16:47+00:00",
      "affects": [
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.2",
          "versions": [
            {
              "version": "1.10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.11.1",
          "versions": [
            {
              "version": "1.11.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:57c656bd-98f8-40c1-aea5-c243bda215dc/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:35f99936-e058-427f-af96-f0b9146b0e20/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:884e3e25-be1a-4fd8-8884-3c120b9e928d/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:8096d075-71fc-4812-99ae-7a123aeae0d0/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:c7b68634-0719-4fa0-91a4-e1d9fef1868f/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:8c4b1904-9db2-4b8a-8fbc-5a5367b88261/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:d753b006-bdd0-4b77-80c7-ba93728cfd9e/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-106450",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        770
      ],
      "description": "yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4FrameInputStream readHeader() allocates two new 4 MiB block buffers whenever a maximum-block-size frame header is read, and the default concatenated-frame mode allows attacker-controlled streams containing many minimal empty frames to trigger roughly 8 MiB of allocation for every 11 input bytes. The stream produces no decompressed output while consuming CPU and garbage-collection time, so decompressed-size limits do not mitigate the issue; readSingleFrame mode is not affected. This issue is fixed in version 1.11.4.",
      "recommendation": "Upgrade at.yawk.lz4:lz4-java to version 1.11.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-106450"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-106450"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-106450"
        },
        {
          "url": "https://github.com/advisories/GHSA-gm45-99xc-r7wv"
        },
        {
          "url": "https://github.com/yawkat/lz4-java"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/commit/2acc0ec1ead226145c62a817c18c8ed49233a283"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/security/advisories/GHSA-gm45-99xc-r7wv"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-106450"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-106450"
        }
      ],
      "published": "2026-10-06T20:17:27+00:00",
      "updated": "2026-10-09T02:16:59+00:00",
      "affects": [
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.2",
          "versions": [
            {
              "version": "1.10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.11.1",
          "versions": [
            {
              "version": "1.11.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:57c656bd-98f8-40c1-aea5-c243bda215dc/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:35f99936-e058-427f-af96-f0b9146b0e20/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:884e3e25-be1a-4fd8-8884-3c120b9e928d/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:8096d075-71fc-4812-99ae-7a123aeae0d0/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:c7b68634-0719-4fa0-91a4-e1d9fef1868f/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:8c4b1904-9db2-4b8a-8fbc-5a5367b88261/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:d753b006-bdd0-4b77-80c7-ba93728cfd9e/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-106451",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        367,
        377
      ],
      "description": "yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by removing the suffix, then FileOutputStream opens that predictable path without exclusive creation, allowing another local user with access to the same shared temporary directory to create or replace the library file before System.load() uses it. Successful exploitation depends on shared-directory permissions, host protections, and winning the race, and can execute native code as the victim; hardened systems may instead cause library loading to fail and fall back to Java implementations. Configurations using a system library, a private java.io.tmpdir, or Java-only implementations are not affected. This issue is fixed in version 1.11.4.",
      "recommendation": "Upgrade at.yawk.lz4:lz4-java to version 1.11.4",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-106451"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-106451"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-106451"
        },
        {
          "url": "https://github.com/advisories/GHSA-mcr4-qmvw-px4g"
        },
        {
          "url": "https://github.com/yawkat/lz4-java"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/commit/7a48b7f6b8099b9dab6541e4ac2ee0979dc55aa3"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/security/advisories/GHSA-mcr4-qmvw-px4g"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-106451"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-106451"
        }
      ],
      "published": "2026-10-06T20:17:27+00:00",
      "updated": "2026-10-07T19:17:32+00:00",
      "affects": [
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.2",
          "versions": [
            {
              "version": "1.10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.11.1",
          "versions": [
            {
              "version": "1.11.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:57c656bd-98f8-40c1-aea5-c243bda215dc/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:35f99936-e058-427f-af96-f0b9146b0e20/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:884e3e25-be1a-4fd8-8884-3c120b9e928d/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:8096d075-71fc-4812-99ae-7a123aeae0d0/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:c7b68634-0719-4fa0-91a4-e1d9fef1868f/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:8c4b1904-9db2-4b8a-8fbc-5a5367b88261/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:d753b006-bdd0-4b77-80c7-ba93728cfd9e/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-106452",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        789
      ],
      "description": "yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen field in a legacy LZ4Block header is nonnegative but allocates a compressed-input buffer of that attacker-controlled size before reading payload data, allowing a header-only stream to request a near-2 GiB allocation and exhaust the JVM heap. Canonical writers emit raw blocks when compression is not smaller than the original block, but vulnerable readers accept non-canonical oversized compressed blocks. This issue is fixed in version 1.11.2.",
      "recommendation": "Upgrade at.yawk.lz4:lz4-java to version 1.11.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-106452"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-106452"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-106452"
        },
        {
          "url": "https://github.com/advisories/GHSA-4v53-57pg-c464"
        },
        {
          "url": "https://github.com/yawkat/lz4-java"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/commit/bb83dd16163cdb71231af06b0a5651881148a634"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/releases/tag/v1.11.2"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/security/advisories/GHSA-4v53-57pg-c464"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-106452"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-106452"
        }
      ],
      "published": "2026-10-06T20:17:27+00:00",
      "updated": "2026-10-07T13:58:29+00:00",
      "affects": [
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.2",
          "versions": [
            {
              "version": "1.10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.11.1",
          "versions": [
            {
              "version": "1.11.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:57c656bd-98f8-40c1-aea5-c243bda215dc/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:35f99936-e058-427f-af96-f0b9146b0e20/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:884e3e25-be1a-4fd8-8884-3c120b9e928d/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:8096d075-71fc-4812-99ae-7a123aeae0d0/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:c7b68634-0719-4fa0-91a4-e1d9fef1868f/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:8c4b1904-9db2-4b8a-8fbc-5a5367b88261/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:d753b006-bdd0-4b77-80c7-ba93728cfd9e/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-106453",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        789
      ],
      "description": "yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ4DecompressorWithLength uses getDecompressedLength to trust the four-byte decompressed-length header before validating the compressed input, allowing a five-byte attacker-supplied input whose header declares a large output size to request up to approximately 2 GiB and exhaust the JVM heap. Convenience overloads backed by LZ4FastDecompressor or LZ4SafeDecompressor allocate the untrusted size, while overloads that write to a caller-provided destination buffer are not affected because the caller controls the destination size. This issue is fixed in version 1.11.2.",
      "recommendation": "Upgrade at.yawk.lz4:lz4-java to version 1.11.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-106453"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-106453"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-106453"
        },
        {
          "url": "https://github.com/advisories/GHSA-6cx8-rjf8-pr8g"
        },
        {
          "url": "https://github.com/yawkat/lz4-java"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/commit/6492ce5aca6bd03ff9e08ee18a2beb94c431371a"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/releases/tag/v1.11.2"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/security/advisories/GHSA-6cx8-rjf8-pr8g"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-106453"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-106453"
        }
      ],
      "published": "2026-10-06T20:17:27+00:00",
      "updated": "2026-10-07T17:16:48+00:00",
      "affects": [
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.2",
          "versions": [
            {
              "version": "1.10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.11.1",
          "versions": [
            {
              "version": "1.11.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:57c656bd-98f8-40c1-aea5-c243bda215dc/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:35f99936-e058-427f-af96-f0b9146b0e20/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:884e3e25-be1a-4fd8-8884-3c120b9e928d/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:8096d075-71fc-4812-99ae-7a123aeae0d0/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:c7b68634-0719-4fa0-91a4-e1d9fef1868f/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:8c4b1904-9db2-4b8a-8fbc-5a5367b88261/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:d753b006-bdd0-4b77-80c7-ba93728cfd9e/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/at.yawk.lz4/lz4-java@1.11.1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-19032",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        470,
        610
      ],
      "description": "jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new URI(value) and then to Path.of(uri). When that throws FileSystemNotFoundException, the code enumerates ServiceLoader<FileSystemProvider> and calls provider.getPath(uri) on the first provider whose scheme matches the attacker-chosen scheme. Untrusted JSON can therefore select and drive an arbitrary registered FileSystemProvider during readValue under a default JsonMapper, and forces provider class loading at the same time. With only the JDK built-in providers (file, jar/zipfs) present, the resolved path is inert and no mount or network I/O occurs; further impact requires a side-effecting third-party FileSystemProvider on the classpath. This affects com.fasterxml.jackson.core:jackson-databind from 2.8.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2. Binding java.nio.file.Path from untrusted JSON should be avoided regardless of version.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.10, 2.21.6, 2.22.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-19032"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-19032"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-19032"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/6129"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19032"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-19032"
        }
      ],
      "published": "2026-09-01T04:18:00+00:00",
      "updated": "2026-09-08T19:29:32+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1",
          "versions": [
            {
              "version": "2.22.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5",
          "versions": [
            {
              "version": "2.21.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:57c656bd-98f8-40c1-aea5-c243bda215dc/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:bfe42d8f-4a36-4766-8c3e-3b61e20ba36d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:35f99936-e058-427f-af96-f0b9146b0e20/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:8096d075-71fc-4812-99ae-7a123aeae0d0/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:c7b68634-0719-4fa0-91a4-e1d9fef1868f/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:8c4b1904-9db2-4b8a-8fbc-5a5367b88261/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:45edb654-e071-4074-a526-e1be8c9141fe/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-59949",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFactory.nativeInstance().newStreamingHash32().update(), and XXHashFactory.nativeInstance().newStreamingHash64().update(), allowing null arrays or oversized ranges to reach native code, read outside the Java array, and fatally terminate the JVM. This issue is fixed in version 1.11.1.",
      "recommendation": "Upgrade at.yawk.lz4:lz4-java to version 1.11.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59949"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59949"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-59949"
        },
        {
          "url": "https://github.com/yawkat/lz4-java"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/releases/tag/v1.11.1"
        },
        {
          "url": "https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59949"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59949"
        }
      ],
      "published": "2026-08-18T15:16:56+00:00",
      "updated": "2026-09-18T20:09:01+00:00",
      "affects": [
        {
          "ref": "pkg:maven/at.yawk.lz4/lz4-java@1.10.2",
          "versions": [
            {
              "version": "1.10.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:57c656bd-98f8-40c1-aea5-c243bda215dc/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:8096d075-71fc-4812-99ae-7a123aeae0d0/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:d753b006-bdd0-4b77-80c7-ba93728cfd9e/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/at.yawk.lz4/lz4-java@1.10.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. Kafka's own bundled LZ4 codec, which every CP repo relies on transitively for record-batch compression, only ever calls the always-safe one-shot XXHash hash() API with non-null, internally-bounded buffers; the vulnerable streaming update() API is never called anywhere in the CP repo set."
      }
    },
    {
      "id": "CVE-2026-68497",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400,
        1333
      ],
      "description": "jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These deserializers are registered by default with no opt-in, so a plain ObjectMapper or JsonMapper with no polymorphic typing and no special configuration reaches this path. The XML Schema lexical grammar permits numeric components of arbitrary length, which the JDK materializes through the native BigInteger(String) and BigDecimal(String) constructors, both quadratic in digit count. Because the digits sit inside a JSON string token rather than a JSON number token, jackson-core's StreamReadConstraints.maxNumberLength guard never applies; jackson's own NumberDeserializers call validateIntegerLength or validateFPLength before parsing a stringified number, but the XML datatype deserializer omits that pre-check. An unauthenticated attacker can therefore submit a single request of a few megabytes, such as a Duration value consisting of the letter P followed by several million digits and the letter Y, and force tens of seconds to several minutes of single-threaded CPU work; a handful of concurrent requests can saturate a server's worker threads. This affects com.fasterxml.jackson.core:jackson-databind from 2.0.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.10, 2.21.6, 2.22.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-68497"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-68497"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-68497"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/6127"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-68497.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-77648.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68497"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-68497"
        }
      ],
      "published": "2026-09-11T16:17:39+00:00",
      "updated": "2026-09-18T19:34:36+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1",
          "versions": [
            {
              "version": "2.22.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5",
          "versions": [
            {
              "version": "2.21.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:57c656bd-98f8-40c1-aea5-c243bda215dc/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:bfe42d8f-4a36-4766-8c3e-3b61e20ba36d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:35f99936-e058-427f-af96-f0b9146b0e20/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:8096d075-71fc-4812-99ae-7a123aeae0d0/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:c7b68634-0719-4fa0-91a4-e1d9fef1868f/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:8c4b1904-9db2-4b8a-8fbc-5a5367b88261/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:45edb654-e071-4074-a526-e1be8c9141fe/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The vulnerable jackson-databind version is present fleet-wide, but no CP repo's own code declares a javax.xml.datatype.Duration or XMLGregorianCalendar field, so the vulnerable deserialization sink cannot be reached."
      }
    },
    {
      "id": "CVE-2026-83557",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        502,
        915
      ],
      "description": "DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of \"unsafe base types\", and its isSafeSubType method returns true unconditionally for every base type outside that set. java.lang.Comparable was absent from the list despite being implemented by a very large fraction of JDK and application classes, comparable in breadth to java.io.Serializable, which is on the list for that reason. An application declaring an @JsonTypeInfo-annotated property or class with Comparable as its base type, and no custom PolymorphicTypeValidator, will accept a type identifier for essentially any class implementing Comparable. This yields an attacker-controlled object instantiation primitive; a demonstrated case constructs a java.io.File for an arbitrary attacker-chosen path, which becomes path-traversal-adjacent if the application subsequently calls path-sensitive methods on the value. No class implementing Comparable has been identified that yields code execution through deserialization alone. Global Default Typing via activateDefaultTyping is not affected, because that method structurally requires an explicit PolymorphicTypeValidator argument. This affects com.fasterxml.jackson.core:jackson-databind from 2.11.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.10, 2.21.6, 2.22.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-83557"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-83557"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-83557"
        },
        {
          "url": "https://getsafety.com/vulnerabilities/SFTY-20260901-46895/CVE-2026-83557"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/6156"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/6155"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83557"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-83557"
        }
      ],
      "published": "2026-09-01T15:17:37+00:00",
      "updated": "2026-09-08T19:29:32+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1",
          "versions": [
            {
              "version": "2.22.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5",
          "versions": [
            {
              "version": "2.21.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:57c656bd-98f8-40c1-aea5-c243bda215dc/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:bfe42d8f-4a36-4766-8c3e-3b61e20ba36d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:35f99936-e058-427f-af96-f0b9146b0e20/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:8096d075-71fc-4812-99ae-7a123aeae0d0/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:c7b68634-0719-4fa0-91a4-e1d9fef1868f/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:8c4b1904-9db2-4b8a-8fbc-5a5367b88261/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:45edb654-e071-4074-a526-e1be8c9141fe/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-89407",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        1333
      ],
      "description": "NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run.\u00a0\n\n\n\nMatching cost therefore grows with the square of the input length.\u00a0\n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float).\u00a0\n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex.\u00a0\n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool.\u00a0\n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected.\u00a0\n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-core to version 2.18.11, 2.21.7, 2.22.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-89407"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-89407"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-89407"
        },
        {
          "url": "https://getsafety.com/vulnerabilities/SFTY-20260922-89449/CVE-2026-89407"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/issues/1649"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/pull/1650"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/pull/1701"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89407"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-89407"
        }
      ],
      "published": "2026-09-22T15:17:21+00:00",
      "updated": "2026-09-22T20:00:03+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1",
          "versions": [
            {
              "version": "2.22.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.5",
          "versions": [
            {
              "version": "2.21.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:57c656bd-98f8-40c1-aea5-c243bda215dc/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:bfe42d8f-4a36-4766-8c3e-3b61e20ba36d/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:35f99936-e058-427f-af96-f0b9146b0e20/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.5"
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:884e3e25-be1a-4fd8-8884-3c120b9e928d/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:8096d075-71fc-4812-99ae-7a123aeae0d0/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:c7b68634-0719-4fa0-91a4-e1d9fef1868f/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:8c4b1904-9db2-4b8a-8fbc-5a5367b88261/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:45edb654-e071-4074-a526-e1be8c9141fe/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.5"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.5"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.5"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.5"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.5"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-89425",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        770
      ],
      "description": "UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-core to version 2.21.7, 2.22.3, 2.18.11",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-89425"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-89425"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-89425"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/pull/1698"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"
        },
        {
          "url": "https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89425"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-89425"
        }
      ],
      "published": "2026-09-23T03:17:04+00:00",
      "updated": "2026-09-24T20:43:32+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1",
          "versions": [
            {
              "version": "2.22.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.5",
          "versions": [
            {
              "version": "2.21.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/tools.jackson.core/jackson-core@3.2.2",
          "versions": [
            {
              "version": "3.2.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:57c656bd-98f8-40c1-aea5-c243bda215dc/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:bfe42d8f-4a36-4766-8c3e-3b61e20ba36d/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:35f99936-e058-427f-af96-f0b9146b0e20/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.5"
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:884e3e25-be1a-4fd8-8884-3c120b9e928d/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:884e3e25-be1a-4fd8-8884-3c120b9e928d/1#pkg:maven/tools.jackson.core/jackson-core@3.2.2"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:8096d075-71fc-4812-99ae-7a123aeae0d0/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:c7b68634-0719-4fa0-91a4-e1d9fef1868f/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:8c4b1904-9db2-4b8a-8fbc-5a5367b88261/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:8c4b1904-9db2-4b8a-8fbc-5a5367b88261/1#pkg:maven/tools.jackson.core/jackson-core@3.2.2"
        },
        {
          "ref": "urn:cdx:45edb654-e071-4074-a526-e1be8c9141fe/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.5"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.5"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/tools.jackson.core/jackson-core@3.2.2"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.5"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/tools.jackson.core/jackson-core@3.2.2"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/tools.jackson.core/jackson-core@3.2.2"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/tools.jackson.core/jackson-core@3.2.2"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/tools.jackson.core/jackson-core@3.2.2"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/tools.jackson.core/jackson-core@3.2.2"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/tools.jackson.core/jackson-core@3.2.2"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/tools.jackson.core/jackson-core@3.2.2"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/tools.jackson.core/jackson-core@3.2.2"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.5"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/tools.jackson.core/jackson-core@3.2.2"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/tools.jackson.core/jackson-core@3.2.2"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.5"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/tools.jackson.core/jackson-core@3.2.2"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-91776",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.18.11, 2.21.7, 2.22.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-91776"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-91776"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-91776"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/6203"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-91776"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-91776"
        }
      ],
      "published": "2026-09-23T03:17:04+00:00",
      "updated": "2026-09-24T20:43:32+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1",
          "versions": [
            {
              "version": "2.22.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5",
          "versions": [
            {
              "version": "2.21.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/tools.jackson.core/jackson-databind@3.2.2",
          "versions": [
            {
              "version": "3.2.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:57c656bd-98f8-40c1-aea5-c243bda215dc/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:bfe42d8f-4a36-4766-8c3e-3b61e20ba36d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:35f99936-e058-427f-af96-f0b9146b0e20/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:884e3e25-be1a-4fd8-8884-3c120b9e928d/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:8096d075-71fc-4812-99ae-7a123aeae0d0/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:c7b68634-0719-4fa0-91a4-e1d9fef1868f/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:8c4b1904-9db2-4b8a-8fbc-5a5367b88261/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:8c4b1904-9db2-4b8a-8fbc-5a5367b88261/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        },
        {
          "ref": "urn:cdx:45edb654-e071-4074-a526-e1be8c9141fe/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-91777",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure.",
      "recommendation": "Upgrade com.fasterxml.jackson.core:jackson-databind to version 2.21.7, 2.18.11, 2.22.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-91777"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-91777"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-91777"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/6204"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/6204"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-91777"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-91777"
        }
      ],
      "published": "2026-09-23T03:17:04+00:00",
      "updated": "2026-09-24T20:43:32+00:00",
      "affects": [
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1",
          "versions": [
            {
              "version": "2.22.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5",
          "versions": [
            {
              "version": "2.21.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/tools.jackson.core/jackson-databind@3.2.2",
          "versions": [
            {
              "version": "3.2.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:57c656bd-98f8-40c1-aea5-c243bda215dc/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:bfe42d8f-4a36-4766-8c3e-3b61e20ba36d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:35f99936-e058-427f-af96-f0b9146b0e20/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:884e3e25-be1a-4fd8-8884-3c120b9e928d/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:8096d075-71fc-4812-99ae-7a123aeae0d0/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:c7b68634-0719-4fa0-91a4-e1d9fef1868f/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:8c4b1904-9db2-4b8a-8fbc-5a5367b88261/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:8c4b1904-9db2-4b8a-8fbc-5a5367b88261/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        },
        {
          "ref": "urn:cdx:45edb654-e071-4074-a526-e1be8c9141fe/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.5"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/tools.jackson.core/jackson-databind@3.2.2"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-49844",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        116
      ],
      "description": "Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0.\n\nThe fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document.\n\nThe defect is reachable only when both of the following conditions hold:\n\n  *  The application uses the  message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message  of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{\"JSON\"}).\n  *  The application logs a MapMessage that contains an attacker-controlled floating-point value.\n\n\nAn attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing.\n\nUsers are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values.",
      "recommendation": "Upgrade org.apache.logging.log4j:log4j-api to version 2.25.5, 2.26.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-49844"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-49844"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-49844"
        },
        {
          "url": "https://github.com/apache/logging-log4j2"
        },
        {
          "url": "https://github.com/apache/logging-log4j2/commit/19edb23e162d6c728a8c2221a240037d389ed300"
        },
        {
          "url": "https://github.com/apache/logging-log4j2/commit/feadf8eb0b4acb6ddfa4c0ab2bbc6d88b8e12d82"
        },
        {
          "url": "https://github.com/apache/logging-log4j2/pull/4163"
        },
        {
          "url": "https://github.com/apache/logging-log4j2/releases/tag/rel/2.25.5"
        },
        {
          "url": "https://github.com/apache/logging-log4j2/releases/tag/rel/2.26.1"
        },
        {
          "url": "https://logging.apache.org/cyclonedx/vdr.xml"
        },
        {
          "url": "https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message"
        },
        {
          "url": "https://logging.apache.org/security.html#CVE-2026-49844"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49844"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-49844"
        }
      ],
      "published": "2026-07-10T22:16:42+00:00",
      "updated": "2026-07-14T20:03:09+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4",
          "versions": [
            {
              "version": "2.25.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35f99936-e058-427f-af96-f0b9146b0e20/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:8c4b1904-9db2-4b8a-8fbc-5a5367b88261/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The MapMessage plus JsonTemplateLayout sink this CVE requires is absent everywhere in CP's 22 repos, and the one genuine MapMessage call site in schroedinger uses an Integer-typed field with a non-vulnerable EcsLayout."
      }
    },
    {
      "id": "CVE-2026-56740",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not limit the number of environment variables a client may inject via the Telnet NEW-ENVIRON option, and TelnetIO.readNEVariables() in TelnetIO.java:1127-1180 stores each variable pair in a HashMap held by ConnectionData, allowing an unauthenticated attacker to flood unique variable pairs before the terminating IAC SE byte and exhaust JVM heap memory with an OutOfMemoryError. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1.",
      "recommendation": "Upgrade org.jline:jline-remote-telnet to version 4.2.1, 4.0.16, 3.30.14",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56740"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56740"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-56740"
        },
        {
          "url": "https://github.com/advisories/GHSA-47qp-hqvx-6r3f"
        },
        {
          "url": "https://github.com/jline/jline3"
        },
        {
          "url": "https://github.com/jline/jline3/commit/0389f0ee6d0375901b602671ad5dafd4d1d4ee09"
        },
        {
          "url": "https://github.com/jline/jline3/commit/4ee3a73849ffb9a85ec748e4e8cd8f6d81f84f40"
        },
        {
          "url": "https://github.com/jline/jline3/commit/934f09e6128cee33c2b13d42b6e859c1ee2d194b"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2000"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2001"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.0.16"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.2.1"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/jline-3.30.14"
        },
        {
          "url": "https://github.com/jline/jline3/security/advisories/GHSA-47qp-hqvx-6r3f"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56740"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56740"
        }
      ],
      "published": "2026-07-17T22:17:57+00:00",
      "updated": "2026-08-18T15:23:04+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.jline/jline-remote-telnet@3.30.4",
          "versions": [
            {
              "version": "3.30.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35f99936-e058-427f-af96-f0b9146b0e20/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. No CP repository constructs or starts a JLine Telnet server anywhere, so the vulnerable NEW-ENVIRON variable-flooding sink in TelnetIO is never reachable."
      }
    },
    {
      "id": "CVE-2026-56741",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not apply an upper bound to terminal dimensions received via the Telnet NAWS option, and TelnetIO.handleNAWS() in TelnetIO.java:856-879 reads client-supplied width and height as 16-bit unsigned integers and passes values such as 65535x65535 to setTerminalGeometry(), allowing an unauthenticated remote attacker to repeatedly alternate values and trigger continuous expensive rendering work that causes CPU exhaustion and denial of service. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1.",
      "recommendation": "Upgrade org.jline:jline-remote-telnet to version 4.2.1, 4.0.16, 3.30.14",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56741"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56741"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-56741"
        },
        {
          "url": "https://github.com/advisories/GHSA-2r2c-cx56-8933"
        },
        {
          "url": "https://github.com/jline/jline3"
        },
        {
          "url": "https://github.com/jline/jline3/commit/3ea9cad8699714dc072fade29d36be0d1e23d708"
        },
        {
          "url": "https://github.com/jline/jline3/commit/733eb353dca7b0ea0252e724445b6defa29c393e"
        },
        {
          "url": "https://github.com/jline/jline3/commit/86b7ba7801988aadb1a67555629522a71d603bd3"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2000"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.0.16"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.2.1"
        },
        {
          "url": "https://github.com/jline/jline3/security/advisories/GHSA-2r2c-cx56-8933"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56741"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56741"
        }
      ],
      "published": "2026-07-17T22:17:57+00:00",
      "updated": "2026-08-18T15:17:51+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.jline/jline-remote-telnet@3.30.4",
          "versions": [
            {
              "version": "3.30.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35f99936-e058-427f-af96-f0b9146b0e20/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.jline/jline-remote-telnet@3.30.4"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. No CP repository constructs or starts a JLine Telnet server anywhere, so the vulnerable NAWS terminal-geometry sink in TelnetIO is never reachable."
      }
    },
    {
      "id": "CVE-2026-77420",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        1333
      ],
      "description": "JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, DefaultHistory.matchPatterns(String patterns, String line) in reader/src/main/java/org/jline/reader/impl/history/DefaultHistory.java converts the HISTORY_IGNORE configuration value into a Java regular expression while escaping only part of its syntax, allowing other regex metacharacters to reach the backtracking engine. An attacker who can control application or user configuration can supply a nested-quantifier expression that is reevaluated whenever a command is added to history, consuming excessive CPU and indefinitely blocking the reader thread. This issue is fixed in versions 3.30.15 and 4.3.1.",
      "recommendation": "Upgrade org.jline:jline-reader to version 4.3.1, 3.30.15",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-77420"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-77420"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-77420"
        },
        {
          "url": "https://github.com/jline/jline3"
        },
        {
          "url": "https://github.com/jline/jline3/commit/1d5fc3099e77938b971e197211cad2d4fbb17541"
        },
        {
          "url": "https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2012"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2018"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.3.1"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/jline-3.30.15"
        },
        {
          "url": "https://github.com/jline/jline3/security/advisories/GHSA-5q95-hrpc-m3w3"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77420"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-77420"
        }
      ],
      "published": "2026-09-23T19:19:15+00:00",
      "updated": "2026-09-30T19:38:27+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.jline/jline-reader@3.30.4",
          "versions": [
            {
              "version": "3.30.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.jline/jline-reader@3.30.14",
          "versions": [
            {
              "version": "3.30.14",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35f99936-e058-427f-af96-f0b9146b0e20/1#pkg:maven/org.jline/jline-reader@3.30.4"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/org.jline/jline-reader@3.30.14"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/org.jline/jline-reader@3.30.4"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/org.jline/jline-reader@3.30.14"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:maven/org.jline/jline-reader@3.30.4"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/org.jline/jline-reader@3.30.4"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/org.jline/jline-reader@3.30.4"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/org.jline/jline-reader@3.30.4"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/org.jline/jline-reader@3.30.4"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/org.jline/jline-reader@3.30.4"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/org.jline/jline-reader@3.30.4"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/org.jline/jline-reader@3.30.4"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/org.jline/jline-reader@3.30.4"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.jline/jline-reader@3.30.4"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.jline/jline-reader@3.30.14"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.jline/jline-reader@3.30.4"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.jline/jline-reader@3.30.14"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-77421",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        1333
      ],
      "description": "JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in nano editor's regex search mode passes a user-controlled search term from doSearch(String text) in builtins/src/main/java/org/jline/builtins/Nano.java to Java's backtracking regular expression engine without a timeout or backtracking bound. A nested-quantifier expression evaluated against non-matching buffer content can consume excessive CPU and indefinitely block the editor session thread, and remote multi-user deployments can lose a worker thread for each affected session. This issue is fixed in versions 3.30.15 and 4.3.1.",
      "recommendation": "Upgrade org.jline:jline-builtins to version 4.3.1, 3.30.15",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-77421"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-77421"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-77421"
        },
        {
          "url": "https://github.com/jline/jline3"
        },
        {
          "url": "https://github.com/jline/jline3/commit/1d5fc3099e77938b971e197211cad2d4fbb17541"
        },
        {
          "url": "https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2012"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2018"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.3.1"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/jline-3.30.15"
        },
        {
          "url": "https://github.com/jline/jline3/security/advisories/GHSA-ph9c-7hw9-vhhw"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77421"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-77421"
        }
      ],
      "published": "2026-09-23T19:19:15+00:00",
      "updated": "2026-09-30T16:44:39+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.jline/jline-builtins@3.30.4",
          "versions": [
            {
              "version": "3.30.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.jline/jline-builtins@3.30.14",
          "versions": [
            {
              "version": "3.30.14",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35f99936-e058-427f-af96-f0b9146b0e20/1#pkg:maven/org.jline/jline-builtins@3.30.4"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/org.jline/jline-builtins@3.30.14"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/org.jline/jline-builtins@3.30.4"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/org.jline/jline-builtins@3.30.14"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:maven/org.jline/jline-builtins@3.30.4"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/org.jline/jline-builtins@3.30.4"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/org.jline/jline-builtins@3.30.4"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/org.jline/jline-builtins@3.30.4"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/org.jline/jline-builtins@3.30.4"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/org.jline/jline-builtins@3.30.4"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/org.jline/jline-builtins@3.30.4"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/org.jline/jline-builtins@3.30.4"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/org.jline/jline-builtins@3.30.4"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.jline/jline-builtins@3.30.4"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.jline/jline-builtins@3.30.14"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.jline/jline-builtins@3.30.4"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.jline/jline-builtins@3.30.14"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-77422",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        1333
      ],
      "description": "JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in grep command in builtins/src/main/java/org/jline/builtins/PosixCommands.java accepts a user-controlled regular expression in grep(...) and, unless line-regexp mode is used, automatically adds a dot-star prefix and suffix before compiling it with Java's backtracking regular expression engine. The wrapping expands the backtracking search space, so a short nested-quantifier expression evaluated against non-matching input can consume excessive CPU and indefinitely block a command worker, including in remotely exposed shell sessions. This issue is fixed in versions 3.30.15 and 4.3.1.",
      "recommendation": "Upgrade org.jline:jline-builtins to version 4.3.1, 3.30.15",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-77422"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-77422"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-77422"
        },
        {
          "url": "https://github.com/jline/jline3"
        },
        {
          "url": "https://github.com/jline/jline3/commit/1d5fc3099e77938b971e197211cad2d4fbb17541"
        },
        {
          "url": "https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2012"
        },
        {
          "url": "https://github.com/jline/jline3/pull/2018"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.3.1"
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/jline-3.30.15"
        },
        {
          "url": "https://github.com/jline/jline3/security/advisories/GHSA-r2xf-8xr9-62gw"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77422"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-77422"
        }
      ],
      "published": "2026-09-23T19:19:15+00:00",
      "updated": "2026-09-30T16:44:39+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.jline/jline-builtins@3.30.4",
          "versions": [
            {
              "version": "3.30.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.jline/jline-builtins@3.30.14",
          "versions": [
            {
              "version": "3.30.14",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:35f99936-e058-427f-af96-f0b9146b0e20/1#pkg:maven/org.jline/jline-builtins@3.30.4"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/org.jline/jline-builtins@3.30.14"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/org.jline/jline-builtins@3.30.4"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/org.jline/jline-builtins@3.30.14"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:maven/org.jline/jline-builtins@3.30.4"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/org.jline/jline-builtins@3.30.4"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/org.jline/jline-builtins@3.30.4"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/org.jline/jline-builtins@3.30.4"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/org.jline/jline-builtins@3.30.4"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/org.jline/jline-builtins@3.30.4"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/org.jline/jline-builtins@3.30.4"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/org.jline/jline-builtins@3.30.4"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/org.jline/jline-builtins@3.30.4"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.jline/jline-builtins@3.30.4"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.jline/jline-builtins@3.30.14"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.jline/jline-builtins@3.30.4"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.jline/jline-builtins@3.30.14"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-107226",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N"
        }
      ],
      "description": "### Impact\nThe cookie store ignores the scheme a `Set-Cookie` arrived on. draft-ietf-httpbis-rfc6265bis-22 (approved to obsolete RFC 6265, in the RFC Editor queue) Section 5.7 requires a user agent to ignore a cookie with the `Secure` attribute unless it arrived over a secure connection (step 13), and to ignore a non-Secure cookie from an insecure connection when it would overlay a Secure cookie the store already holds (step 16). Neither rule is implemented. The only `Secure` handling is on retrieval, where a Secure cookie is not sent over plaintext.\n\nSo anyone who can answer a plaintext request to a site can set, replace or delete the site's `Secure` cookies, and the next HTTPS request carries the attacker's value back inside TLS:\n\n```\nhttp://example.com   ->  Set-Cookie: SID=attacker-value; Secure; Path=/\nhttps://example.com  ->  Cookie: SID=attacker-value\n```\n\nThis does not need an attacker on the network path. A plaintext host under the same site reaches the HTTPS one by setting a domain cookie:\n\n```\nhttp://insecure.example.com  ->  Set-Cookie: SID=attacker-value; Secure; Domain=example.com; Path=/\nhttps://bank.example.com     ->  Cookie: SID=attacker-value\n```\n\nA plaintext `Set-Cookie` of the same name, domain and path overwrites a Secure cookie, and one with `Max-Age=0` deletes it. Depending on what the application does with the cookie, this is session fixation into the HTTPS session, an overwritten CSRF token, or the removal of a cookie the site relies on. Unlike GHSA-qjr7-w8pj-pmv9, which can only add a cookie, this replaces or deletes one, hence Integrity: High; the harm lands on the HTTPS site, hence Scope: Changed.\n\n### Affected versions\n* 3.x: up to and including 3.0.13\n* 2.x: from 2.1.0, when the cookie store was introduced, up to and including 2.16.1\n\n### Patches\nFixed in 3.0.14 on the 3.x line. A cookie with the `Secure` attribute is ignored unless the request was secure, and a non-Secure cookie from a request that did not use TLS is ignored when it would overlay a Secure cookie of the same name whose path its own path falls under. A plaintext response can therefore no longer plant, overwrite or delete a `Secure` cookie.\n\nWhen several cookies of one name match a request, the client sends only the first, so the order in which the store returns them decides which one is used. That order is now: on a secure request, cookies received in a secure context (HTTPS, WSS or plaintext loopback) first; then the request host's own cookies before cookies set for a parent domain; then, within one host, longer paths first. A plaintext attacker cannot outrank a cookie the site set over HTTPS by ordering or padding its own cookies, or by setting one before the site sets its own.\n\nPlaintext requests to `localhost`, or to an address literal that is a loopback address, count as secure, so a development server that sets `Secure` cookies over `http://localhost` gets them back. This is limited to the cookies such a server set itself: a `Secure` cookie that arrived over HTTPS is never sent over plaintext, loopback included, and a plaintext loopback port cannot overlay it. Numeric spellings that are not address literals, such as `127.0.0.256`, and names under `localhost` are not treated as loopback, because the client resolves them as names.\n\nThe 2.x line is end of life and will not receive a fix. Upgrade to 3.0.14.\n\n### Workarounds\nDo not share one `CookieStore` between plaintext and HTTPS origins that are not mutually trusted, including hosts under the same site. Disabling the cookie store also avoids it.\n\n### Details\n`ThreadSafeCookieStore.add(Uri, Cookie)` reduces the request to its host and path before storing, so the scheme never reaches the code that decides whether to keep a cookie. `get(Uri)` does read it, but only to leave `Secure` cookies out of plaintext requests.\n\nA narrower form survives the two storage rules on their own. The step 16 path test is one-way by design, so a plaintext `SID` for `Path=/` is legitimately stored beside a Secure `SID` for `Path=/account`, and both match a request under `/account`. The store returned matching cookies in hash order, and the client keeps only the first cookie of each name when it builds the request (`RequestBuilderBase.addCookieIfUnset`), so an attacker could decide which one was sent, for example by padding one plaintext response with filler cookies. The ordering described above closes it.\n\nThe fix does not stop an HTTPS host under the same site from setting a domain cookie for a name the request host never sets itself. Only a `__Host-` cookie name prefix prevents that, and the client does not enforce cookie name prefixes.\n\n### Attribution\n\nAI-assisted tools were used to support discovery and analysis.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.14",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107226"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/6ec7ee45034d154f502852a962d2891746fb82c1"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-p2jm-6hj6-9rjg"
        }
      ],
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-107227",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        409
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.2.0 until 3.0.14, WebSocket permessage-deflate decompression is unbounded when compression is enabled. The inbound pipeline aggregates compressed frames before WebSocketClientCompressionHandler inflates them, so webSocketMaxFrameSize and webSocketMaxBufferSize do not bound decompressed output. A malicious WebSocket peer can send a small compressed message that expands to a very large Netty buffer and exhausts JVM heap. This issue is fixed in version 3.0.14.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.14",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107227"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-107227"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-x8v2-478q-2hvg"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107227"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-107227"
        }
      ],
      "published": "2026-10-07T21:17:14+00:00",
      "updated": "2026-10-08T20:35:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-107228",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        287
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 3.0.14, the enabled-by-default cookie store replaces a Cookie header explicitly supplied through setHeader or addHeader whenever the store contributes any cookie for the origin. In a shared client, stored cookies originating from one user can replace a different user's request cookie, causing the request to execute under the wrong session. This bypasses the earlier CVE-2024-53990 remediation, which covered cookies supplied through addCookie but not a directly supplied header. This issue is fixed in version 3.0.14.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.14",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107228"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-2jwh-9rmr-j4xf"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107228"
        }
      ],
      "published": "2026-10-07T21:17:14+00:00",
      "updated": "2026-10-08T20:35:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-107230",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        346,
        863
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 3.0.14, connection-pool partitioning still omits identity-defining fields for Kerberos, SPNEGO, NTLM, and authenticated proxy connections. Logins without a configured principal, proxy realms, identities sharing a user name, and SOCKS or CONNECT proxy logins can reuse a socket authenticated as a different identity. A later request is then executed under the first identity and can expose that identity's data or authority to another caller. In the affected execution path, SpnegoEngine, NTLM, Kerberos, SPNEGO, SOCKS, and CONNECT control or expose the vulnerable behavior. This issue is fixed in version 3.0.14.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.14",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107230"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-107230"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-v2j5-22fr-j62r"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107230"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-107230"
        }
      ],
      "published": "2026-10-07T22:17:03+00:00",
      "updated": "2026-10-08T20:35:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-107231",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        319,
        522,
        757
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, Realm.Builder treats a Digest challenge that yields no usable nonce as a Basic challenge. A malicious origin or proxy can label a challenge Digest while omitting or emptying the nonce, causing the client to resend the username and password using reversible Basic authentication. Both origin and proxy challenge parsers are affected. This issue is fixed in versions 3.0.13 and 2.16.1.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.13, 2.16.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107231"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-107231"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/8376866aa9b5a7653ad19db9d472692f875caa83"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/c8d639bf6ac341d377d610a93570bcd15565f1a6"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-rqf5-2wxv-rjf4"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107231"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-107231"
        }
      ],
      "published": "2026-10-07T22:17:03+00:00",
      "updated": "2026-10-08T20:35:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-107280",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [],
      "cwes": [
        1275
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13  and 2.16.1, ThreadSafeCookieStore validates Domain attributes with domain matching but does not reject public suffixes. A host beneath a suffix such as co.uk can set a cookie for that suffix, after which the shared cookie store sends it to unrelated hosts under the suffix. This can inject or overwrite session-relevant cookie values across origins. This issue is fixed in versions 3.0.13 and 2.16.1.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.13, 2.16.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107280"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/330267895fe0bdb41bbd027ea6b151d38ee7c23d"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/d1f0ccec417092098d40242fee7dfac84bb3c21f"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-f9m8-cv68-674w"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107280"
        }
      ],
      "published": "2026-10-07T22:17:03+00:00",
      "updated": "2026-10-08T20:35:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-107282",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [],
      "cwes": [
        319,
        441,
        522
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13  and 2.16.1, cross-host request replay updates the current request but leaves the target request and related proxy context pointing at the original origin. Connection-pool selection, CONNECT handling, realm selection, and TLS setup can consequently send the original host's path, Host header, Authorization credentials, or plaintext request to the replay destination. Documented ResponseFilter failover and retry paths can trigger the replay. This issue is fixed in versions 3.0.13 and 2.16.1.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.13, 2.16.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107282"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/15b254514a411623e5f1d8c99ea79c0f82f8a466"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/bbc31aed3b044f9f7a126cf689a8c8d7ad2ae1cb"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-jmqq-x5g9-9p2w"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107282"
        }
      ],
      "published": "2026-10-07T22:17:04+00:00",
      "updated": "2026-10-08T20:35:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-107283",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        338
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12  and 2.16.1, Realm.Builder generates the HTTP Digest client nonce with ThreadLocalRandom rather than a cryptographically secure random source. Digest relies on an unpredictable cnonce to resist chosen-plaintext and credential precomputation attacks, so an observer able to infer generator state can reduce the protection of the authentication exchange. This issue is fixed in versions 3.0.12 and 2.16.1.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.12, 2.16.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107283"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/dca2d90db87f0144ea893a6858dca13c426d06b6"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/e1f5fc88fe211d3f64032c33b91093ba3d5e793d"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-mfj3-87qq-382v"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107283"
        }
      ],
      "published": "2026-10-07T22:17:04+00:00",
      "updated": "2026-10-08T20:35:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-107285",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        319,
        522
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, a proxied ws request is carried through CONNECT, but NettyRequestFactory.newNettyRequest and requestUri decide whether to attach proxy authentication and an absolute-form target only from whether the URI is secure. Because ws is not marked secure, the tunneled WebSocket upgrade sent to the origin includes the proxy's Proxy-Authorization value. Basic credentials are directly recoverable and Digest responses can be replayed or cracked offline. This issue is fixed in versions 3.0.12 and 2.16.1.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.12, 2.16.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107285"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/6e9cb75a9b7259353f983fc90ca28b1da3742e18"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/c4feab0f7f86d61505a48e40d383c8a375a22e18"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-3wp9-xfwm-rjjf"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107285"
        }
      ],
      "published": "2026-10-07T22:17:04+00:00",
      "updated": "2026-10-08T20:35:31+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-54399",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser\u00a0in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows\u00a0an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of headers / excessive header length",
      "recommendation": "Upgrade org.apache.httpcomponents.core5:httpcore5 to version 5.4.3, 5.5-beta2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54399"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/01/4"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54399"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-54399"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core/commit/d96a00fec9b2e19f8005e35681df5f6cd6e21a9e"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core/commit/fdc53a32fe0fccf098cc67e71cd125e447c759ed"
        },
        {
          "url": "https://lists.apache.org/thread/zmxh1pl2zohov5ntdh4lt85gfrlchgpy"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54399"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54399"
        }
      ],
      "published": "2026-07-01T17:16:36+00:00",
      "updated": "2026-07-24T20:04:03+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4",
          "versions": [
            {
              "version": "5.3.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4",
          "versions": [
            {
              "version": "5.3.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:884e3e25-be1a-4fd8-8884-3c120b9e928d/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:45edb654-e071-4074-a526-e1be8c9141fe/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.3.4"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-54428",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        770
      ],
      "description": "Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied.",
      "recommendation": "Upgrade org.apache.httpcomponents.core5:httpcore5-h2 to version 5.4.3, 5.5-beta2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54428"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/01/3"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54428"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-54428"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core/commit/1ea1239bbbe3442a8382a87279c0a8119a7e358e"
        },
        {
          "url": "https://github.com/apache/httpcomponents-core/commit/cc30ee058a7b10cbf4ad3dd6270ab6d1f6a74c49"
        },
        {
          "url": "https://lists.apache.org/thread/5zjp8vczvxq19pw2rvhs21q446bhl0sd"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54428"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54428"
        }
      ],
      "published": "2026-07-01T18:16:34+00:00",
      "updated": "2026-07-24T20:03:41+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4",
          "versions": [
            {
              "version": "5.3.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4",
          "versions": [
            {
              "version": "5.3.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:884e3e25-be1a-4fd8-8884-3c120b9e928d/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:45edb654-e071-4074-a526-e1be8c9141fe/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.3.4"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in Confluent Platform because httpcore5-h2 is present only as a client-side transitive dependency; no CP component runs an HTTP/2 server built on this library. This issue will be addressed in an upcoming release when an updated package is available from the vendor."
      }
    },
    {
      "id": "CVE-2026-55688",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1275
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In versions from 2.0.0 prior to 2.16.0 and from 3.0.0.Beta1 prior to 3.0.11, ThreadSafeCookieStore stored a cookie under the value of its Domain attribute without verifying that the responding host is allowed to set a cookie for that domain, leading to a cookie tossing / cookie injection issue. A host the client connects to can therefore plant a cookie scoped to an unrelated domain, and the client will then send that cookie on later requests to that domain. Applications that use a single AsyncHttpClient instance - and thus the default, shared CookieStore - to reach both an attacker-influenced host and a trusted host are impacted. This issue has been fixed in versions 2.16.0 and 3.0.11.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.11, 2.16.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-55688"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-55688"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-55688"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/8e4069cf3c92abe099db5fb13378ac2fe9e1fd3b"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/e6955c1e3951cf80e286981d064f6c926ce33f47"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/pull/2196"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/pull/2199"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.0"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.11"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-m452-q8c9-rg2f"
        },
        {
          "url": "https://github.com/advisories/GHSA-m452-q8c9-rg2f"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/08/msg00011.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55688"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8655-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-55688"
        }
      ],
      "published": "2026-07-01T20:17:11+00:00",
      "updated": "2026-08-06T22:17:52+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in Confluent Platform because async-http-client is used only for a single, fixed, internal Druid telemetry endpoint; no mixed-trust multi-host scenario exists for this CVE's cookie-tossing mechanism to apply. This issue will be addressed in an upcoming release when an updated package is available from the vendor."
      }
    },
    {
      "id": "CVE-2026-59903",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "cwes": [
        524
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie with Origin, allowing a caching proxy or CDN to reuse authenticated responses across users and disclose sensitive information. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.",
      "recommendation": "Upgrade io.netty:netty-codec-http to version 4.2.17.Final, 4.1.137.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59903"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59903"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-59903"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/pull/17213"
        },
        {
          "url": "https://github.com/netty/netty/pull/17217"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.137.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-8c42-7qj2-3j46"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59903"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59903"
        }
      ],
      "published": "2026-08-17T18:17:36+00:00",
      "updated": "2026-09-23T15:21:27+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.136.Final",
          "versions": [
            {
              "version": "4.1.136.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.136.Final",
          "versions": [
            {
              "version": "4.1.136.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.2.16.Final",
          "versions": [
            {
              "version": "4.2.16.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/io.netty/netty-codec-http@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:884e3e25-be1a-4fd8-8884-3c120b9e928d/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/io.netty/netty-codec-http@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/io.netty/netty-codec-http@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:8096d075-71fc-4812-99ae-7a123aeae0d0/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:8c4b1904-9db2-4b8a-8fbc-5a5367b88261/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/io.netty/netty-codec-http@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/io.netty/netty-codec-http@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/io.netty/netty-codec-http@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/io.netty/netty-codec-http@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/io.netty/netty-codec-http@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/io.netty/netty-codec-http@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/io.netty/netty-codec-http@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/io.netty/netty-codec-http@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/io.netty/netty-codec-http@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/io.netty/netty-codec-http@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/io.netty/netty-codec-http@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/io.netty/netty-codec-http@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/io.netty/netty-codec-http@4.2.16.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in Confluent Platform because corsHandler.setVaryHeader is never invoked by conflux's AWS SDK Netty client, which only ever performs outbound HTTP/1.1 and HTTP/2 requests to AWS S3/DynamoDB; the vulnerable server-side code path is not present in its actual usage. This issue will be addressed in an upcoming release when an updated package is available from the vendor."
      }
    },
    {
      "id": "CVE-2026-64607",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        772
      ],
      "description": "HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message.\u00a0Please note this defect does not affect HttpClient based on the async i/o model.\n\nThis issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.",
      "recommendation": "Upgrade org.apache.httpcomponents.client5:httpclient5 to version 5.6.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-64607"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/08/13/5"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-64607"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-64607"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client/commit/55733f4121f7ba26ddf04fe12739d9c15962cb94"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client/commit/ebac9512f555c4a355cad3f59ef2db69b597cc97"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client/releases/tag/rel/v5.6.3"
        },
        {
          "url": "https://github.com/apache/httpcomponents-client/releases/tag/rel/v5.7-alpha1"
        },
        {
          "url": "https://lists.apache.org/thread/qqfzo3fqcdk4l5496vz95ppvl4ty511q"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64607"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-64607"
        }
      ],
      "published": "2026-07-31T11:17:11+00:00",
      "updated": "2026-08-13T17:17:33+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4",
          "versions": [
            {
              "version": "5.4.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4",
          "versions": [
            {
              "version": "5.4.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:884e3e25-be1a-4fd8-8884-3c120b9e928d/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:45edb654-e071-4074-a526-e1be8c9141fe/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.4"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-75595",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        754
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so a ClientHello whose handshake header spans records can cause an IndexOutOfBoundsException and invoke select(ctx, null). This selects the default SslContext instead of the SNI-specific context. In deployments where per-SNI clientAuth=REQUIRE is the sole mutual TLS gate, the default SslContext uses clientAuth=NONE or clientAuth=OPTIONAL, and no application-layer certificate verification exists, an unauthenticated remote attacker can bypass the protected route's mutual TLS requirement. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.",
      "recommendation": "Upgrade io.netty:netty-handler to version 4.2.17.Final, 4.1.137.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-75595"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-75595"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-75595"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7"
        },
        {
          "url": "https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961"
        },
        {
          "url": "https://github.com/netty/netty/pull/17213"
        },
        {
          "url": "https://github.com/netty/netty/pull/17217"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.137.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-c4c3-7fpv-j4q5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75595"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75595"
        }
      ],
      "published": "2026-08-19T21:17:37+00:00",
      "updated": "2026-09-22T19:33:26+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.136.Final",
          "versions": [
            {
              "version": "4.1.136.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.136.Final",
          "versions": [
            {
              "version": "4.1.136.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.2.16.Final",
          "versions": [
            {
              "version": "4.2.16.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:884e3e25-be1a-4fd8-8884-3c120b9e928d/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:8096d075-71fc-4812-99ae-7a123aeae0d0/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:8c4b1904-9db2-4b8a-8fbc-5a5367b88261/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. The vulnerable Netty SslClientHelloHandler is present only as a transitive outbound-client dependency across CP repos; no in-scope repo wires it into a per-SNI, per-clientAuth-varying inbound TLS listener, so the bypass mechanism cannot fire."
      }
    },
    {
      "id": "CVE-2026-75596",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        407
      ],
      "description": "Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHandler constructors use the pre-handshake ClientHello aggregation path in handler/src/main/java/io/netty/handler/ssl/SslClientHelloHandler.java at io.netty.handler.ssl.SslClientHelloHandler#decode, where handshakeBuffer.clear() and writeBytes() recopy all previously received body bytes for every additional TLS record. An unauthenticated remote peer can advertise a large ClientHello and deliver its body in thousands of tiny records, causing quadratic CPU work on the event loop before the TLS handshake completes and degrading TLS handling for other clients. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.",
      "recommendation": "Upgrade io.netty:netty-handler to version 4.2.17.Final, 4.1.137.Final",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-75596"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-75596"
        },
        {
          "url": "https://github.com/netty/netty"
        },
        {
          "url": "https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7"
        },
        {
          "url": "https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961"
        },
        {
          "url": "https://github.com/netty/netty/pull/17213"
        },
        {
          "url": "https://github.com/netty/netty/pull/17217"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.137.Final"
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"
        },
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-fccg-mwvh-qqg4"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75596"
        }
      ],
      "published": "2026-08-19T21:17:37+00:00",
      "updated": "2026-09-22T19:28:32+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.136.Final",
          "versions": [
            {
              "version": "4.1.136.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.136.Final",
          "versions": [
            {
              "version": "4.1.136.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.2.16.Final",
          "versions": [
            {
              "version": "4.2.16.Final",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:884e3e25-be1a-4fd8-8884-3c120b9e928d/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:8096d075-71fc-4812-99ae-7a123aeae0d0/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:8c4b1904-9db2-4b8a-8fbc-5a5367b88261/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/io.netty/netty-handler@4.1.136.Final"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/io.netty/netty-handler@4.2.16.Final"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-85716",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        287,
        390
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, processScramAuthenticationInfo and processAuthenticationInfo compute the SCRAM ServerSignature or Digest rspauth verification result but log a mismatch and still deliver the response as authenticated. On a non-TLS or compromised transport, a peer that has not proved knowledge of the shared secret can therefore be accepted as the server. The fix rejects a present invalid value and computes Digest rspauth from the Authorization parameters actually sent, but verification remains unenforced when the value is absent, the sent parameters cannot be recovered, or Digest uses qop=auth-int. This issue is fixed in version 3.0.12.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.12",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-85716"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-85716"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/10b3db9910f0bbad2ea3dc7c7553bae12bc4a5e4"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/685173afea07892462071d966ef6ce5c88cbc66f"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/7fe8700fd5b46c668cee7774624f36b87b9dd32a"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/pull/2235"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-fj9w-c36g-h5x8"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85716"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-85716"
        }
      ],
      "published": "2026-09-17T17:16:50+00:00",
      "updated": "2026-09-24T21:16:28+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-85717",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        200,
        522
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.14.5 to 2.16.0 and from 3.0.9 to 3.0.11, a client configured with a client-wide Realm and redirect following can disclose credentials after a cross-origin redirect because the Interceptors authentication path falls back to the client configuration after redirect handling clears the per-exchange realm. If the attacker-controlled target returns 401, the client can send Basic or Digest credentials or a Negotiate or NTLM token to that origin. Per-request realms are stripped correctly, and this issue is a residual bypass of the earlier cross-origin credential-stripping fixes. This issue is fixed in versions 2.16.1 and 3.0.12.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.12, 2.16.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-85717"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-85717"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/43db7bba81430cbd61ec2dc2c7be464e0ff6a0ff"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/b66757bec34def2e9867bb2b77bd848b1112abb4"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/pull/2224"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-f8m2-889x-vw4x"
        },
        {
          "url": "https://github.com/advisories/GHSA-f8m2-889x-vw4x"
        }
      ],
      "published": "2026-09-17T16:18:15+00:00",
      "updated": "2026-09-30T17:31:44+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-85720",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        319,
        522
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, a request using an HTTP proxy to reach an HTTPS origin can expose preemptive origin credentials because NettyRequestFactory and NettyRequestSender.sendRequestWithNewChannel attach Authorization to the plaintext CONNECT request before the TLS tunnel exists. Basic or Digest credentials and per-connection NTLM, Kerberos, or SPNEGO tokens intended for the origin are therefore visible to the proxy and to observers on the client-to-proxy hop. The tunneled request still receives origin Authorization after the tunnel is established, while Proxy-Authorization remains on CONNECT for its intended proxy recipient. This issue is fixed in versions 2.16.1 and 3.0.12.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.12, 2.16.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-85720"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-85720"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/9dba5ac988b7e750551f59b2eab550b60ac8a0d6"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/d07dbc79f5cf378f63c246f6101d7579ace55acc"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/pull/2234"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-xr57-gcx8-52hf"
        },
        {
          "url": "https://github.com/advisories/GHSA-xr57-gcx8-52hf"
        }
      ],
      "published": "2026-09-17T17:16:51+00:00",
      "updated": "2026-09-24T21:16:28+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-85721",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400,
        409
      ],
      "description": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, automatic response decompression on the HTTP/1.1 path uses ChannelManager.newHttpContentDecompressor() to install Http1ContentDecompressor without a cumulative output-size limit. A hostile or compromised server, or an attacker who can alter a response in transit, can send a small gzip, deflate, or snappy response that expands across chunks until the client exhausts its heap and raises OutOfMemoryError; brotli and zstd are also affected when their optional codecs are present. In versions 3.0.8 through 3.0.10, the HTTP/2 decompressor is also unbounded, so switching protocols does not mitigate the issue on those releases. A limit applied to each decode call is insufficient because the response can be delivered as many small chunks, so the fixed implementation tracks total decompressed bytes for the whole response. This issue is fixed in versions 2.16.1 and 3.0.12.",
      "recommendation": "Upgrade org.asynchttpclient:async-http-client to version 3.0.12, 2.16.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-85721"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-85721"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-85721"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/5ee2841cbf268bba4a200578be3938ccfc6cc6d6"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/663a1a91757904b22cfe37e2e6049f1f8ea6ae59"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/e1871a19972fb496be1b8ac6be11d79e22ff2162"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/e9f2f7423e0f6503f529656f2955a1317e56ba14"
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-7grg-jcf7-rpmx"
        },
        {
          "url": "https://github.com/advisories/GHSA-7grg-jcf7-rpmx"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85721"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-85721"
        }
      ],
      "published": "2026-09-17T16:18:16+00:00",
      "updated": "2026-09-30T17:43:24+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:maven/org.asynchttpclient/async-http-client@3.0.10",
          "versions": [
            {
              "version": "3.0.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:ce5215fd-bd9f-489f-b9d9-2bbd6cf1fd6a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.asynchttpclient/async-http-client@3.0.10"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-13505",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        772
      ],
      "description": "In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), sensitive key material held by the AES and DESede engines, the SP 800-90A DRBGs, SymmetricSecretKey and the PBKD and scrypt parameter classes was zeroised on garbage collection by overriding Object.finalize. Finalization runs at an unspecified time and in an unspecified order and is serviced by a single finalizer thread, so where objects carrying a finalizer are allocated faster than that thread retires them the pending-finalization queue grows without bound: disposal falls arbitrarily far behind, which can contribute to an OutOfMemoryError under load, and the key material those objects hold stays resident in the heap for as long as they are queued, defeating the purpose of the zeroisation. The behaviour was not a problem on Java 8 or Java 11; it is later JVMs, on which finalization has been deprecated and progressively de-emphasised, where it becomes one. Disposal of these classes now runs from a java.lang.ref.Cleaner registered in the multi-release jdk1.9 overlay, so on Java 9 and later it no longer depends on the finalizer being scheduled. Bouncy Castle for Java (bcprov) and Bouncy Castle for Java LTS are not affected, as neither implements the finalizer-based zeroisation scheme.",
      "recommendation": "Upgrade org.bouncycastle:bc-fips to version 1.0.2.7, 2.0.2, 2.1.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-13505"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-13505"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-13505"
        },
        {
          "url": "https://github.com/advisories/GHSA-98j2-6v39-78w8"
        },
        {
          "url": "https://github.com/bcgit/bc-java"
        },
        {
          "url": "https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9013505"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13505"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13505"
        }
      ],
      "published": "2026-08-08T02:17:16+00:00",
      "updated": "2026-09-03T16:44:20+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bc-fips@2.1.2",
          "versions": [
            {
              "version": "2.1.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:8096d075-71fc-4812-99ae-7a123aeae0d0/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-13506",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        674
      ],
      "description": "In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).",
      "recommendation": "Upgrade org.bouncycastle:bc-fips to version 1.0.2.7, 2.0.2, 2.1.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-13506"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-13506"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-13506"
        },
        {
          "url": "https://github.com/advisories/GHSA-qp49-qgx5-5m26"
        },
        {
          "url": "https://github.com/bcgit/bc-java"
        },
        {
          "url": "https://github.com/bcgit/bc-java/commit/77454da9b3dcaaa2991412d1c3c1a6e1a338ff84"
        },
        {
          "url": "https://github.com/bcgit/bc-java/wiki/CVE-2026-13506"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13506"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13506"
        }
      ],
      "published": "2026-08-03T04:16:39+00:00",
      "updated": "2026-08-28T16:41:22+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bc-fips@2.1.2",
          "versions": [
            {
              "version": "2.1.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:8096d075-71fc-4812-99ae-7a123aeae0d0/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-8763",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        295
      ],
      "description": "In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).",
      "recommendation": "Upgrade org.bouncycastle:bc-fips to version 1.0.2.7, 2.0.2, 2.1.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8763"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8763"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-8763"
        },
        {
          "url": "https://github.com/advisories/GHSA-9pwp-9qqc-pr26"
        },
        {
          "url": "https://github.com/bcgit/bc-java"
        },
        {
          "url": "https://github.com/bcgit/bc-java/commit/2c28b253a44681fbbc562561eab6ad383d2ae558"
        },
        {
          "url": "https://github.com/bcgit/bc-java/releases/tag/r1rv85v2"
        },
        {
          "url": "https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908763"
        },
        {
          "url": "https://github.com/bcgit/bc-java/wiki/CVE-2026-8763"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8763"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8763"
        }
      ],
      "published": "2026-08-03T01:16:45+00:00",
      "updated": "2026-09-02T14:28:48+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bc-fips@2.1.2",
          "versions": [
            {
              "version": "2.1.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:8096d075-71fc-4812-99ae-7a123aeae0d0/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-8798",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [],
      "cwes": [
        835
      ],
      "description": "In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the native entropy source used on Intel platforms retried the CPU entropy instructions without any bound. RDSEED and RDRAND report failure through their carry flag, and the JNI seeding routine spun re-issuing the instruction for as long as that flag stayed clear, so a persistent failure of the on-chip entropy source - whether from a hardware fault, from the underlying DRBG being exhausted by contention across many cores, or from a hypervisor that does not provide the instruction - left the calling thread looping indefinitely inside the JNI call, where it could be neither interrupted nor timed out. Any operation drawing from the native entropy source could therefore hang, denying service to the application. The retry loops are now bounded (200 attempts for RDSEED and 20 for RDRAND, twice the baselines given in Intel's Digital Random Number Generator software implementation guide), pausing between attempts and, on exhaustion, clearing any partially written buffer and throwing rather than continuing to spin. The clear is performed by an un-elidable memzero, which uses a volatile pointer and an assembly memory barrier so that a compiler cannot optimise the erase away as a dead store. Bouncy Castle for Java (bcprov) is not affected, as it has no native entropy source; the 1.0.X and 2.0.X FIPS series are not affected.",
      "recommendation": "Upgrade org.bouncycastle:bc-fips to version 2.1.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8798"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-8798"
        },
        {
          "url": "https://github.com/advisories/GHSA-v6w3-qrh8-qccc"
        },
        {
          "url": "https://github.com/bcgit/bc-java"
        },
        {
          "url": "https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908798"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8798"
        }
      ],
      "published": "2026-08-08T01:16:31+00:00",
      "updated": "2026-09-03T16:44:20+00:00",
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bc-fips@2.1.2",
          "versions": [
            {
              "version": "2.1.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:dcc7a9e5-3fe6-4a53-ab78-8643b792145a/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:ca99a440-cc9d-49ea-ba0e-6e225bd2edc8/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:8096d075-71fc-4812-99ae-7a123aeae0d0/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:f62b92bc-a0b9-4d86-b82e-507525d2789e/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        },
        {
          "ref": "urn:cdx:84cab4a8-de27-48b7-9860-4536e54bf078/1#pkg:maven/org.bouncycastle/bc-fips@2.1.2"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-45292",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Amaven"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        770
      ],
      "description": "opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API. Prior to 1.62.0, a vulnerability affects the baggage propagation implementation in opentelemetry-api and opentelemetry-extension-trace-propagators. Parsing oversized baggage causes unbounded memory allocation and CPU consumption. Because baggage is automatically re-injected into every outgoing request, the effect can fan out to downstream services that never received the original malicious request. This vulnerability is fixed in 1.62.0.",
      "recommendation": "Upgrade io.opentelemetry:opentelemetry-api to version 1.62.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-45292"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28573"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36820"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41951"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43038"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60520"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-45292"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-45292"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2482785"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-java"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-java/commit/03837d3c1763bc35464aea1078671e2ef2336a5f"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-java/pull/8380"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-java/releases/tag/v1.62.0"
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-java/security/advisories/GHSA-rcgg-9c38-7xpx"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45292"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45292.json"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45292"
        }
      ],
      "published": "2026-05-28T17:16:32+00:00",
      "updated": "2026-09-10T13:20:17+00:00",
      "affects": [
        {
          "ref": "pkg:maven/io.opentelemetry/opentelemetry-api@1.42.1",
          "versions": [
            {
              "version": "1.42.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:3c60067a-f135-4b33-a6a3-190fe82dd6db/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.1"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:maven/io.opentelemetry/opentelemetry-api@1.42.1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available. the OpenTelemetry W3C Baggage propagator is not wired to parse inbound request headers, so the unbounded baggage-allocation path is not reachable."
      }
    },
    {
      "id": "CVE-2005-2541",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 10,
          "severity": "high",
          "method": "CVSSv2",
          "vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "description": "Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2005-2541"
        },
        {
          "url": "http://marc.info/?l=bugtraq&m=112327628230258&w=2"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2005-2541"
        },
        {
          "url": "https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c@%3Cissues.guacamole.apache.org%3E"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2005-2541"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2005-2541"
        }
      ],
      "published": "2005-08-10T04:00:00+00:00",
      "updated": "2026-04-16T00:27:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.34-13.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.34-13.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/tar@1.34-13.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2021-31879",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.8,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:P/I:P/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        601
      ],
      "description": "GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-31879"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-31879"
        },
        {
          "url": "https://mail.gnu.org/archive/html/bug-wget/2021-02/msg00002.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-31879"
        },
        {
          "url": "https://savannah.gnu.org/bugs/?56909"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20210618-0002/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-31879"
        }
      ],
      "published": "2021-04-29T05:15:08+00:00",
      "updated": "2026-10-08T21:17:35+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.21.1-11.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-11.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/wget@1.21.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2021-3572",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.7,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.5,
          "severity": "info",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:S/C:N/I:P/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        20
      ],
      "description": "A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-3572"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2021:3254"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-3572"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1772014"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1928707"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1928904"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1935913"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1941534"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1955615"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1957458"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1962856"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1968074"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18874"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27619"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28493"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20095"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23336"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28957"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29921"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33503"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3426"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3572"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42771"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2021:4162"
        },
        {
          "url": "https://github.com/advisories/GHSA-5xp3-jfq3-5q8x"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2021-437.yaml"
        },
        {
          "url": "https://github.com/pypa/pip"
        },
        {
          "url": "https://github.com/pypa/pip/commit/e46bdda9711392fec0c45c1175bae6db847cb30b"
        },
        {
          "url": "https://github.com/pypa/pip/issues/10042"
        },
        {
          "url": "https://github.com/pypa/pip/issues/10042#issuecomment-857452480"
        },
        {
          "url": "https://github.com/pypa/pip/pull/9827"
        },
        {
          "url": "https://github.com/skazi0/CVE-2021-3572/blob/master/CVE-2021-3572-v9.0.1.patch"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2021-3572.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2023-12349.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-3572"
        },
        {
          "url": "https://packetstormsecurity.com/files/162712/USN-4961-1.txt"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240621-0006"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240621-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-4961-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-3572"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuapr2022.html"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2022.html"
        }
      ],
      "published": "2021-11-10T18:15:09+00:00",
      "updated": "2026-10-08T21:17:40+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "21.3.1-2.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2021-46195",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        674
      ],
      "description": "GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by consuming excessive CPU and memory resources.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2021-46195"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2022:8415"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-46195"
        },
        {
          "url": "https://bugzilla.redhat.com/2046300"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2022-8415.html"
        },
        {
          "url": "https://gcc.gnu.org/bugzilla/show_bug.cgi?id=103841"
        },
        {
          "url": "https://gcc.gnu.org/git/?p=gcc.git;a=commit;h=f10bec5ffa487ad3033ed5f38cfd0fc7d696deab"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2021-46195.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2022-8415.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-46195"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-46195"
        }
      ],
      "published": "2022-01-14T20:15:15+00:00",
      "updated": "2026-10-08T22:17:14+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2022-27943",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv2",
          "vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        674
      ],
      "description": "libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2022-27943"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2022-27943"
        },
        {
          "url": "https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039"
        },
        {
          "url": "https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=1a770b01ef415e114164b6151d1e55acdee09371"
        },
        {
          "url": "https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=9234cdca6ee88badfc00297e72f13dac4e540c79"
        },
        {
          "url": "https://gcc.gnu.org/git/gitweb.cgi?p=gcc.git;h=fc968115a742d9e4674d9725ce9c2106b91b6ead"
        },
        {
          "url": "https://gcc.gnu.org/pipermail/gcc-patches/2022-March/592244.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27943"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=28995"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-27943"
        }
      ],
      "published": "2022-03-26T13:15:07+00:00",
      "updated": "2026-10-08T19:16:56+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2022-3219",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2022-3219"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2022-3219"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2127010"
        },
        {
          "url": "https://dev.gnupg.org/D556"
        },
        {
          "url": "https://dev.gnupg.org/T5993"
        },
        {
          "url": "https://marc.info/?l=oss-security&m=165696590211434&w=4"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3219"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230324-0001/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-3219"
        }
      ],
      "published": "2023-02-23T20:15:12+00:00",
      "updated": "2026-06-17T04:59:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.3.3-5.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2022-41409",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        190
      ],
      "description": "Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2022-41409"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2022-41409"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/commit/94e1c001761373b7d9450768aa15d04c25547a35"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/issues/141"
        },
        {
          "url": "https://github.com/advisories/GHSA-4qfx-v7wh-3q4j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41409"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-41409"
        }
      ],
      "published": "2023-07-18T14:15:12+00:00",
      "updated": "2026-06-17T05:03:09+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-30571",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "cwes": [
        362
      ],
      "description": "Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race condition with another thread can lead to a permanent umask 0 setting. Such a race condition could lead to implicit directory creation with permissions 0777 (without the sticky bit), which means that any low-privileged local user can delete and rename files inside those directories.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-30571"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-30571"
        },
        {
          "url": "https://access.redhat.com/solutions/7033331"
        },
        {
          "url": "https://github.com/libarchive/libarchive/issues/1876"
        },
        {
          "url": "https://groups.google.com/g/libarchive-announce"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30571"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-30571"
        }
      ],
      "published": "2023-05-29T20:15:09+00:00",
      "updated": "2026-06-17T05:55:03+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-11.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-32636",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400,
        502
      ],
      "description": "A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-32636"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:2528"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-32636"
        },
        {
          "url": "https://bugzilla.redhat.com/2211827"
        },
        {
          "url": "https://bugzilla.redhat.com/2211828"
        },
        {
          "url": "https://bugzilla.redhat.com/2211829"
        },
        {
          "url": "https://bugzilla.redhat.com/2211833"
        },
        {
          "url": "https://discourse.gnome.org/t/multiple-fixes-for-gvariant-normalisation-issues-in-glib/12835"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-2528.html"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/2841"
        },
        {
          "url": "https://https://discourse.gnome.org/t/multiple-fixes-for-gvariant-normalisation-issues-in-glib/12835"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-32636.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-2528.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32636"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20231110-0002/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6165-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-32636"
        }
      ],
      "published": "2023-09-14T20:15:09+00:00",
      "updated": "2026-06-17T05:59:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-39804",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-39804"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-39804"
        },
        {
          "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1058079"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/tar.git/commit/?id=a339f05cd269013fa133d2f148d73f6f7d4247e4"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/tar.git/tree/src/xheader.c?h=release_1_34#n1723"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00008.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39804"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6543-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-39804"
        }
      ],
      "published": "2024-03-27T04:15:08+00:00",
      "updated": "2026-06-17T06:12:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.34-13.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.34-13.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/tar@1.34-13.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-4156",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-4156"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-4156"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2215930"
        },
        {
          "url": "https://git.savannah.gnu.org/gitweb/?p=gawk.git;a=commitdiff;h=e709eb829448ce040087a3fc5481db6bfcaae212"
        },
        {
          "url": "https://mail.gnu.org/archive/html/bug-gawk/2022-08/msg00000.html"
        },
        {
          "url": "https://mail.gnu.org/archive/html/bug-gawk/2022-08/msg00023.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4156"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6373-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-4156"
        }
      ],
      "published": "2023-09-25T18:15:11+00:00",
      "updated": "2026-06-17T06:37:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "5.1.0-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-45322",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        416
      ],
      "description": "libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is \"I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail.\"",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-45322"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2023/10/06/5"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-45322"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/344"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/583"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45322"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-45322"
        }
      ],
      "published": "2023-10-06T22:15:11+00:00",
      "updated": "2026-06-17T06:28:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-45803",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        200
      ],
      "description": "urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303 after the request had its method changed from one that could accept a request body (like `POST`) to `GET` as is required by HTTP RFCs. Although this behavior is not specified in the section for redirects, it can be inferred by piecing together information from different sections and we have observed the behavior in other major HTTP client implementations like curl and web browsers. Because the vulnerability requires a previously trusted service to become compromised in order to have an impact on confidentiality we believe the exploitability of this vulnerability is low. Additionally, many users aren't putting sensitive data in HTTP request bodies, if this is the case then this vulnerability isn't exploitable. Both of the following conditions must be true to be affected by this vulnerability: 1. Using urllib3 and submitting sensitive information in the HTTP request body (such as form data or JSON) and 2. The origin service is compromised and starts redirecting using 301, 302, or 303 to a malicious peer or the redirected-to service becomes compromised. This issue has been addressed in versions 1.26.18 and 2.0.7 and users are advised to update to resolve this issue. Users unable to update should disable redirects for services that aren't expecting to respond with redirects with `redirects=False` and disable automatic redirects with `redirects=False` and handle 301, 302, and 303 redirects manually by stripping the HTTP request body.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-45803"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:11238"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2024:2132"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-45803"
        },
        {
          "url": "https://bugzilla.redhat.com/2246840"
        },
        {
          "url": "https://bugzilla.redhat.com/2257028"
        },
        {
          "url": "https://bugzilla.redhat.com/2257854"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2246840"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45803"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2024-2132.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2024:11238"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2023-212.yaml"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/4e50fbc5db74e32cabd5ccc1ab81fc103adfe0b3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/4e98d57809dacab1cbe625fddeec1a290c478ea9"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/b594c5ceaca38e1ac215f916538fb128e3526a36"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/1.26.18"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/2.0.7"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-g4mx-q9vg-27p4"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2023-45803.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2024-2988.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00020.html"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4R2Y5XK3WALSR3FNAGN7JBYV2B343ZKB"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4R2Y5XK3WALSR3FNAGN7JBYV2B343ZKB/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5F5CUBAN5XMEBVBZPHFITBLMJV5FIJJ5"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5F5CUBAN5XMEBVBZPHFITBLMJV5FIJJ5/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PPDPLM6UUMN55ESPQWJFLLIZY4ZKCNRX"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PPDPLM6UUMN55ESPQWJFLLIZY4ZKCNRX/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45803"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6473-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6473-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7762-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-45803"
        },
        {
          "url": "https://www.rfc-editor.org/rfc/rfc9110.html#name-get"
        }
      ],
      "published": "2023-10-17T20:15:10+00:00",
      "updated": "2026-06-17T06:29:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "21.3.1-2.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2023-50495",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "description": "NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2023-50495"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2023-50495"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"
        },
        {
          "url": "https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html"
        },
        {
          "url": "https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50495"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240119-0008/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6684-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-50495"
        }
      ],
      "published": "2023-12-12T15:15:07+00:00",
      "updated": "2026-06-17T06:39:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "6.2-12.20210508.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "6.2-12.20210508.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-0232",
      "ratings": [
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        416
      ],
      "description": "A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-0232"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-0232"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2243754"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QDCMYQ3J45NHQ4EJREM3BJNNKB5BK4Y7/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0232"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240315-0007/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-0232"
        }
      ],
      "published": "2024-01-16T14:15:48+00:00",
      "updated": "2026-06-17T06:53:02+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.34.1-11.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-10524",
      "ratings": [
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L"
        }
      ],
      "cwes": [
        918
      ],
      "description": "Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-10524"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/11/18/6"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-10524"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/wget.git/commit/?id=c419542d956a2607bbce5df64b9d378a8588d778"
        },
        {
          "url": "https://github.com/advisories/GHSA-mqrm-h2pw-9j9r"
        },
        {
          "url": "https://jfrog.com/blog/cve-2024-10524-wget-zero-day-vulnerability"
        },
        {
          "url": "https://jfrog.com/blog/cve-2024-10524-wget-zero-day-vulnerability/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10524"
        },
        {
          "url": "https://seclists.org/oss-sec/2024/q4/107"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250321-0007"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250321-0007/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-10524"
        }
      ],
      "published": "2024-11-19T15:15:06+00:00",
      "updated": "2026-06-17T06:55:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.21.1-11.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-11.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/wget@1.21.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-11053",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.4,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "description": "When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, curl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.\n\nThis flaw only manifests itself if the netrc file has an entry that matches\nthe redirect target hostname but the entry either omits just the password or\nomits both login and password.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-11053"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/12/11/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:1671"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-11053"
        },
        {
          "url": "https://bugzilla.redhat.com/2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/2339305"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339305"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-11053.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-11053.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11053"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21193"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21194"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21196"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21197"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21198"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21201"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21203"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21212"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21213"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21218"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21219"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21230"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21231"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21236"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21237"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21238"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21239"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21241"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21247"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-37371"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5535"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7264"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21490"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21491"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21494"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21497"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21500"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21501"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21503"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21504"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21505"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21518"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21520"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21521"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21522"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21523"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21525"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21529"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21531"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21534"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21536"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21540"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21543"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21546"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21555"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21559"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-1671.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:1671"
        },
        {
          "url": "https://github.com/advisories/GHSA-h288-5fq8-5pfw"
        },
        {
          "url": "https://hackerone.com/reports/2829063"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-11053.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-1673.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11053"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0012"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0012/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0003"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0003/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0004"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250131-0004/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7162-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-11053"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpujan2025.html#AppendixMSQL"
        }
      ],
      "published": "2024-12-11T08:15:05+00:00",
      "updated": "2026-06-17T06:56:57+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-13176",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        385
      ],
      "description": "Issue summary: A timing side-channel which could potentially allow recovering\nthe private key exists in the ECDSA signature computation.\n\nImpact summary: A timing side-channel in ECDSA signature computations\ncould allow recovering the private key by an attacker. However, measuring\nthe timing would require either local access to the signing application or\na very fast network connection with low latency.\n\nThere is a timing signal of around 300 nanoseconds when the top word of\nthe inverted ECDSA nonce value is zero. This can happen with significant\nprobability only for some of the supported elliptic curves. In particular\nthe NIST P-521 curve is affected. To be able to measure this leak, the attacker\nprocess must either be located in the same physical computer or must\nhave a very fast network connection with low latency. For that reason\nthe severity of this vulnerability is Low.\n\nThe FIPS modules in 3.4, 3.3, 3.2, 3.1 and 3.0 are affected by this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-13176"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/01/20/2"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:15699"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:16046"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-13176"
        },
        {
          "url": "https://bugzilla.redhat.com/2359885"
        },
        {
          "url": "https://bugzilla.redhat.com/2359888"
        },
        {
          "url": "https://bugzilla.redhat.com/2359892"
        },
        {
          "url": "https://bugzilla.redhat.com/2359894"
        },
        {
          "url": "https://bugzilla.redhat.com/2359895"
        },
        {
          "url": "https://bugzilla.redhat.com/2359899"
        },
        {
          "url": "https://bugzilla.redhat.com/2359900"
        },
        {
          "url": "https://bugzilla.redhat.com/2359902"
        },
        {
          "url": "https://bugzilla.redhat.com/2359903"
        },
        {
          "url": "https://bugzilla.redhat.com/2359911"
        },
        {
          "url": "https://bugzilla.redhat.com/2359918"
        },
        {
          "url": "https://bugzilla.redhat.com/2359920"
        },
        {
          "url": "https://bugzilla.redhat.com/2359924"
        },
        {
          "url": "https://bugzilla.redhat.com/2359928"
        },
        {
          "url": "https://bugzilla.redhat.com/2359930"
        },
        {
          "url": "https://bugzilla.redhat.com/2359932"
        },
        {
          "url": "https://bugzilla.redhat.com/2359934"
        },
        {
          "url": "https://bugzilla.redhat.com/2359938"
        },
        {
          "url": "https://bugzilla.redhat.com/2359940"
        },
        {
          "url": "https://bugzilla.redhat.com/2359943"
        },
        {
          "url": "https://bugzilla.redhat.com/2359944"
        },
        {
          "url": "https://bugzilla.redhat.com/2359945"
        },
        {
          "url": "https://bugzilla.redhat.com/2359947"
        },
        {
          "url": "https://bugzilla.redhat.com/2359950"
        },
        {
          "url": "https://bugzilla.redhat.com/2359963"
        },
        {
          "url": "https://bugzilla.redhat.com/2359964"
        },
        {
          "url": "https://bugzilla.redhat.com/2359972"
        },
        {
          "url": "https://bugzilla.redhat.com/2370920"
        },
        {
          "url": "https://bugzilla.redhat.com/2380264"
        },
        {
          "url": "https://bugzilla.redhat.com/2380273"
        },
        {
          "url": "https://bugzilla.redhat.com/2380274"
        },
        {
          "url": "https://bugzilla.redhat.com/2380278"
        },
        {
          "url": "https://bugzilla.redhat.com/2380280"
        },
        {
          "url": "https://bugzilla.redhat.com/2380283"
        },
        {
          "url": "https://bugzilla.redhat.com/2380284"
        },
        {
          "url": "https://bugzilla.redhat.com/2380290"
        },
        {
          "url": "https://bugzilla.redhat.com/2380291"
        },
        {
          "url": "https://bugzilla.redhat.com/2380295"
        },
        {
          "url": "https://bugzilla.redhat.com/2380298"
        },
        {
          "url": "https://bugzilla.redhat.com/2380306"
        },
        {
          "url": "https://bugzilla.redhat.com/2380308"
        },
        {
          "url": "https://bugzilla.redhat.com/2380309"
        },
        {
          "url": "https://bugzilla.redhat.com/2380310"
        },
        {
          "url": "https://bugzilla.redhat.com/2380312"
        },
        {
          "url": "https://bugzilla.redhat.com/2380313"
        },
        {
          "url": "https://bugzilla.redhat.com/2380320"
        },
        {
          "url": "https://bugzilla.redhat.com/2380321"
        },
        {
          "url": "https://bugzilla.redhat.com/2380322"
        },
        {
          "url": "https://bugzilla.redhat.com/2380326"
        },
        {
          "url": "https://bugzilla.redhat.com/2380327"
        },
        {
          "url": "https://bugzilla.redhat.com/2380334"
        },
        {
          "url": "https://bugzilla.redhat.com/2380335"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2338999"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359892"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359894"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359895"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359899"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359900"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359902"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359903"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359911"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359918"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359920"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359924"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359928"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359930"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359934"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359938"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359940"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359943"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359944"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359945"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359947"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359950"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359963"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359964"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359972"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370920"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380264"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380273"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380274"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380278"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380280"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380283"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380284"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380290"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380291"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380295"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380298"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380306"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380308"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380309"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380310"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380312"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380313"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380320"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380321"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380322"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380326"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380327"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380334"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2380335"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-13176"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21574"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21575"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21577"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21579"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21580"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21581"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21584"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21585"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21588"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30681"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30682"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30683"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30684"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30685"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30687"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30688"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30689"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30693"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30695"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30696"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30699"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30703"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30704"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30705"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30715"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30721"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30722"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50077"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50078"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50079"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50080"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50081"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50082"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50083"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50084"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50085"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50086"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50087"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50088"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50091"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50092"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50093"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50094"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50096"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50097"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50098"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50099"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50100"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50101"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50102"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50104"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5399"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-16046.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:15699"
        },
        {
          "url": "https://github.com/advisories/GHSA-r9fv-h47r-823f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/07272b05b04836a762b4baa874958af51d513844"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2af62e74fb59bc469506bc37eb2990ea408d9467"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/392dcb336405a0c94486aa6655057f59fd3a0902"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4b1cb94a734a7d4ec363ac0a215a25c181e11f65"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/77c608f4c8857e63e98e66444e2e761c9627916f"
        },
        {
          "url": "https://github.openssl.org/openssl/extended-releases/commit/0d5fd1ab987f7571e2c955d8d8b638fc0fb54ded"
        },
        {
          "url": "https://github.openssl.org/openssl/extended-releases/commit/a2639000db19878d5d89586ae7b725080592ae86"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-13176.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-16046.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00028.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13176"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20250120.txt"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0005"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250124-0005/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250418-0010"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250418-0010/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250502-0006"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250502-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7264-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7278-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-13176"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuapr2025.html#AppendixMSQL"
        }
      ],
      "published": "2025-01-20T14:15:26+00:00",
      "updated": "2026-06-17T07:01:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-25260",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-25260"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-25260"
        },
        {
          "url": "https://github.com/schsiung/fuzzer_issues/issues/1"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25260"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=31058"
        },
        {
          "url": "https://sourceware.org/elfutils/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7369-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-25260"
        }
      ],
      "published": "2024-02-20T18:15:52+00:00",
      "updated": "2026-06-17T07:15:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-29040",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        502
      ],
      "description": "This repository hosts source code implementing the Trusted Computing Group's (TCG) TPM2 Software Stack (TSS). The JSON Quote Info returned by Fapi_Quote has to be deserialized by Fapi_VerifyQuote to the TPM Structure `TPMS_ATTEST`. For the field `TPM2_GENERATED magic` of this structure any number can be used in the JSON structure. The verifier can receive a state which does not represent the actual, possibly malicious state of the device under test. The malicious device might get access to data it shouldn't, or can use services it shouldn't be able to. This \nissue has been patched in version 4.1.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-29040"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-29040"
        },
        {
          "url": "https://github.com/tpm2-software/tpm2-tss/commit/710cd0b6adf3a063f34a8e92da46df7a107d9a99"
        },
        {
          "url": "https://github.com/tpm2-software/tpm2-tss/releases/tag/4.1.0"
        },
        {
          "url": "https://github.com/tpm2-software/tpm2-tss/security/advisories/GHSA-837m-jw3m-h9p6"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EFR7SVEWCOXORHPCLLGXEMHFMIGG2MFE/"
        },
        {
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GI4JFEZBKQQUPJ4RWK6IHEWXAFCEJDPI/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29040"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6796-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-29040"
        }
      ],
      "published": "2024-06-28T21:15:02+00:00",
      "updated": "2026-06-17T07:22:18+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tpm2-tss@3.2.3-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.2.3-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/tpm2-tss@3.2.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/tpm2-tss@3.2.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/tpm2-tss@3.2.3-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-41996",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        295
      ],
      "description": "Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-41996"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-41996"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-089022.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-485750.html"
        },
        {
          "url": "https://dheatattack.gitlab.io/details/"
        },
        {
          "url": "https://dheatattack.gitlab.io/faq/"
        },
        {
          "url": "https://gist.github.com/c0r0n3r/abccc14d4d96c0442f3a77fa5ca255d1"
        },
        {
          "url": "https://github.com/openssl/openssl/issues/17374"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41996"
        },
        {
          "url": "https://openssl-library.org/post/2022-10-21-tls-groups-configuration/"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-41996"
        }
      ],
      "published": "2024-08-26T06:15:04+00:00",
      "updated": "2026-06-17T07:48:36+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-7264",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an\nASN.1 Generalized Time field. If given an syntactically incorrect field, the\nparser might end up using -1 for the length of the *time fraction*, leading to\na `strlen()` getting performed on a pointer to a heap buffer area that is not\n(purposely) null terminated.\n\nThis flaw most likely leads to a crash, but can also lead to heap contents\ngetting returned to the application when\n[CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-7264"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/07/31/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:1671"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-7264"
        },
        {
          "url": "https://bugzilla.redhat.com/2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/2339305"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294581"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294676"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2301888"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318857"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318858"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318870"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318873"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318874"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318876"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318882"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318883"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318884"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318885"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318886"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318897"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318900"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318905"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318914"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318922"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318923"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318925"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318926"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318927"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2331191"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339218"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339220"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339221"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339226"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339231"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339236"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339238"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339243"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339247"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339252"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339259"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339266"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339270"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339271"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339275"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339277"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339281"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339284"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339291"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339293"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339295"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339299"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339300"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339304"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339305"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-7264.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-7264.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11053"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21193"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21194"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21196"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21197"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21198"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21199"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21201"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21203"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21212"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21213"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21218"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21219"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21230"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21231"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21236"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21237"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21238"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21239"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21241"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21247"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-37371"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5535"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7264"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21490"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21491"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21494"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21497"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21500"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21501"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21503"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21504"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21505"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21518"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21520"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21521"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21522"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21523"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21525"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21529"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21531"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21534"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21536"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21540"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21543"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21546"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21555"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21559"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-1671.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:1671"
        },
        {
          "url": "https://github.com/curl/curl/commit/27959ecce75cdb2809c0bdb3286e60e08fadb519"
        },
        {
          "url": "https://hackerone.com/reports/2629968"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2024-7264.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-1673.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7264"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240828-0008/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20241025-0006/"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20241025-0010/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6944-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-6944-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-7264"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuoct2024.html#AppendixMSQL"
        }
      ],
      "published": "2024-07-31T08:15:02+00:00",
      "updated": "2026-06-17T08:19:43+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2024-9681",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        697
      ],
      "description": "When curl is asked to use HSTS, the expiry time for a subdomain might\noverwrite a parent domain's cache entry, making it end sooner or later than\notherwise intended.\n\nThis affects curl using applications that enable HSTS and use URLs with the\ninsecure `HTTP://` scheme and perform transfers with hosts like\n`x.example.com` as well as `example.com` where the first host is a subdomain\nof the second host.\n\n(The HSTS cache either needs to have been populated manually or there needs to\nhave been previous HTTPS accesses done as the cache needs to have entries for\nthe domains involved to trigger this problem.)\n\nWhen `x.example.com` responds with `Strict-Transport-Security:` headers, this\nbug can make the subdomain's expiry timeout *bleed over* and get set for the\nparent domain `example.com` in curl's HSTS cache.\n\nThe result of a triggered bug is that HTTP accesses to `example.com` get\nconverted to HTTPS for a different period of time than what was asked for by\nthe origin server. If `example.com` for example stops supporting HTTPS at its\nexpiry time, curl might then fail to access `http://example.com` until the\n(wrongly set) timeout expires. This bug can also expire the parent's entry\n*earlier*, thus making curl inadvertently switch back to insecure HTTP earlier\nthan otherwise intended.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2024-9681"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/12"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/13"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/4"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/5"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/8"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/9"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2024/11/06/2"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2024-9681"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-9681.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2024-9681.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-g337-g667-mjvw"
        },
        {
          "url": "https://hackerone.com/reports/2764830"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9681"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20241213-0006"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20241213-0006/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7104-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-9681"
        }
      ],
      "published": "2024-11-06T08:15:03+00:00",
      "updated": "2026-06-17T08:25:03+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-11468",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        93
      ],
      "description": "When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-11468"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-11468"
        },
        {
          "url": "https://github.com/python/cpython/commit/003b8315669b9f08b1010a49071f73f15f818094"
        },
        {
          "url": "https://github.com/python/cpython/commit/17d1490aa97bd6b98a42b1a9b324ead84e7fd8a2"
        },
        {
          "url": "https://github.com/python/cpython/commit/61614a5e5056e4f61ced65008d4576f3df34acb6"
        },
        {
          "url": "https://github.com/python/cpython/commit/a76e4cd62dd68e7cbe86e37e6ed988495a646b66"
        },
        {
          "url": "https://github.com/python/cpython/commit/e9970f077240c7c670e8a6fc6662f2b30d3b6ad0"
        },
        {
          "url": "https://github.com/python/cpython/commit/f738386838021c762efea6c9802c82de65e87796"
        },
        {
          "url": "https://github.com/python/cpython/issues/143935"
        },
        {
          "url": "https://github.com/python/cpython/pull/143936"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/FELSEOLBI2QR6YLG6Q7VYF7FWSGQTKLI/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-11468"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-11468"
        }
      ],
      "published": "2026-01-20T22:15:50+00:00",
      "updated": "2026-06-17T08:30:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-11961",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 1.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        122,
        126
      ],
      "description": "pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer.  The string argument must be a well-formed MAC-48 address in one of the supported formats, but this requirement has been poorly documented.  If an application calls the function with an argument that deviates from the expected format, the function can read data beyond the end of the provided string and write data beyond the end of the allocated buffer.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-11961"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-11961"
        },
        {
          "url": "https://github.com/the-tcpdump-group/libpcap/commit/b2d2f9a9a0581c40780bde509f7cc715920f1c02"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-11961"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-11961"
        }
      ],
      "published": "2025-12-31T01:15:54+00:00",
      "updated": "2026-06-17T08:31:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14",
          "versions": [
            {
              "version": "14:1.10.0-4.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-12781",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        704
      ],
      "description": "When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python.\u00a0Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-12781"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-12781"
        },
        {
          "url": "https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b"
        },
        {
          "url": "https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947"
        },
        {
          "url": "https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5"
        },
        {
          "url": "https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76"
        },
        {
          "url": "https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5"
        },
        {
          "url": "https://github.com/python/cpython/issues/125346"
        },
        {
          "url": "https://github.com/python/cpython/pull/141128"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-12781"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-12781"
        }
      ],
      "published": "2026-01-21T20:16:04+00:00",
      "updated": "2026-06-17T08:32:56+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-13034",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        295
      ],
      "description": "When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey`\nwith the curl tool, curl should check the public key of the server certificate\nto verify the peer.\n\nThis check was skipped in a certain condition that would then make curl allow\nthe connection without performing the proper check, thus not noticing a\npossible impostor. To skip this check, the connection had to be done with QUIC\nwith ngtcp2 built to use GnuTLS and the user had to explicitly disable the\nstandard certificate verification.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-13034"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-13034"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-13034.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-13034.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-9r76-qj98-jfhc"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13034"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-13034"
        }
      ],
      "published": "2026-01-08T10:15:45+00:00",
      "updated": "2026-09-15T07:16:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-13462",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        20,
        74,
        434
      ],
      "description": "The \"tarfile\" module would still apply normalization of AREGTYPE (\\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-13462"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-13462"
        },
        {
          "url": "https://github.com/python/cpython/commit/42d754e34c06e57ad6b8e7f92f32af679912d8ab"
        },
        {
          "url": "https://github.com/python/cpython/commit/72dde1016493c52abe857fc4a7bf6c40138b4114"
        },
        {
          "url": "https://github.com/python/cpython/commit/7ad3093d76a748af55bdb1d2e8aad3638163b017"
        },
        {
          "url": "https://github.com/python/cpython/commit/9a23b753552afa28e3a2f4d8863572fc66479406"
        },
        {
          "url": "https://github.com/python/cpython/commit/ae99fe3a33b43e303a05f012815cef60b611a9c7"
        },
        {
          "url": "https://github.com/python/cpython/commit/d10950739a78f54d0718d88fb5a868374603c084"
        },
        {
          "url": "https://github.com/python/cpython/issues/141707"
        },
        {
          "url": "https://github.com/python/cpython/pull/143934"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/EOMI5I66ZMKQ2INNFT6T7IAIKUGPZYIE/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13462"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-13462"
        }
      ],
      "published": "2026-03-12T18:16:21+00:00",
      "updated": "2026-08-13T01:16:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-1371",
      "ratings": [
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        404,
        476
      ],
      "description": "A vulnerability has been found in GNU elfutils 0.192 and classified as problematic. This vulnerability affects the function handle_dynamic_symtab of the file readelf.c of the component eu-read. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is identified as b38e562a4c907e08171c76b8b2def8464d5a104a. It is recommended to apply a patch to fix this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-1371"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-1371"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1371"
        },
        {
          "url": "https://sourceware.org/bugzilla/attachment.cgi?id=15926"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32655"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32655#c2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7369-1"
        },
        {
          "url": "https://vuldb.com/?ctiid.295978"
        },
        {
          "url": "https://vuldb.com/?id.295978"
        },
        {
          "url": "https://vuldb.com/?submit.496484"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1371"
        },
        {
          "url": "https://www.gnu.org/"
        }
      ],
      "published": "2025-02-17T03:15:09+00:00",
      "updated": "2026-06-17T08:39:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-1376",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        404
      ],
      "description": "A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is b16f441cca0a4841050e3215a9f120a6d8aea918. It is recommended to apply a patch to fix this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-1376"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-1376"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1376"
        },
        {
          "url": "https://sourceware.org/bugzilla/attachment.cgi?id=15940"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32672"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32672#c3"
        },
        {
          "url": "https://vuldb.com/?ctiid.295984"
        },
        {
          "url": "https://vuldb.com/?id.295984"
        },
        {
          "url": "https://vuldb.com/?submit.497538"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1376"
        },
        {
          "url": "https://www.gnu.org/"
        }
      ],
      "published": "2025-02-17T05:15:09+00:00",
      "updated": "2026-06-17T08:39:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-1377",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        404
      ],
      "description": "A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the function gelf_getsymshndx of the file strip.c of the component eu-strip. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is fbf1df9ca286de3323ae541973b08449f8d03aba. It is recommended to apply a patch to fix this issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-1377"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-1377"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1377"
        },
        {
          "url": "https://sourceware.org/bugzilla/attachment.cgi?id=15941"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32673"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32673#c2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7369-1"
        },
        {
          "url": "https://vuldb.com/?ctiid.295985"
        },
        {
          "url": "https://vuldb.com/?id.295985"
        },
        {
          "url": "https://vuldb.com/?submit.497539"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1377"
        },
        {
          "url": "https://www.gnu.org/"
        }
      ],
      "published": "2025-02-17T05:15:10+00:00",
      "updated": "2026-06-17T08:39:01+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.194-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/elfutils-default-yama-scope@0.194-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/elfutils-libelf@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/elfutils-libs@0.194-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-13837",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-13837"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-13837"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/568342cfc8f002d9a15f30238f26b9d2e0e79036"
        },
        {
          "url": "https://github.com/python/cpython/commit/5a8b19677d818fb41ee55f310233772e15aa1a2b"
        },
        {
          "url": "https://github.com/python/cpython/commit/694922cf40aa3a28f898b5f5ee08b71b4922df70"
        },
        {
          "url": "https://github.com/python/cpython/commit/71fa8eb8233b37f16c88b6e3e583b461b205d1ba"
        },
        {
          "url": "https://github.com/python/cpython/commit/b64441e4852383645af5b435411a6f849dd1b4cb"
        },
        {
          "url": "https://github.com/python/cpython/commit/cefee7d118a26ef6cd43db59bb9d98ca9a331111"
        },
        {
          "url": "https://github.com/python/cpython/issues/119342"
        },
        {
          "url": "https://github.com/python/cpython/pull/119343"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-13837.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/2X5IBCJXRQAZ5PSERLHMSJFBHFR3QM2C/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13837"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-13837"
        }
      ],
      "published": "2025-12-01T18:16:04+00:00",
      "updated": "2026-09-03T03:15:21+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-14017",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        567
      ],
      "description": "When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,\nchanging TLS options in one thread would inadvertently change them globally\nand therefore possibly also affect other concurrently setup transfers.\n\nDisabling certificate verification for a specific transfer could\nunintentionally disable the feature for other threads as well.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-14017"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/3"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-14017"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14017.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14017.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-jh4h-2cg6-889h"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14017"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-14017"
        }
      ],
      "published": "2026-01-08T10:15:45+00:00",
      "updated": "2026-09-15T07:16:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-14524",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        522,
        601
      ],
      "description": "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a cross-protocol redirect to a second URL that uses an IMAP, LDAP,\nPOP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new\ntarget host.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-14524"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/4"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-14524"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14524.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-14524.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-g897-jvjx-78vg"
        },
        {
          "url": "https://hackerone.com/reports/3459417"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14524"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-14524"
        }
      ],
      "published": "2026-01-08T10:15:46+00:00",
      "updated": "2026-09-15T07:16:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-15079",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        297
      ],
      "description": "When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-15079"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/6"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-15079"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15079.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15079.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-7q9p-cx8r-rh2q"
        },
        {
          "url": "https://hackerone.com/reports/3477116"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15079"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-15079"
        }
      ],
      "published": "2026-01-08T10:15:47+00:00",
      "updated": "2026-09-15T07:16:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-15224",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        287
      ],
      "description": "When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-15224"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/07/7"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-15224"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15224.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2025-15224.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-hccr-q52r-4w88"
        },
        {
          "url": "https://hackerone.com/reports/3480925"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15224"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8062-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-15224"
        }
      ],
      "published": "2026-01-08T10:15:47+00:00",
      "updated": "2026-09-15T07:16:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-15282",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        93
      ],
      "description": "User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-15282"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-15282"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/05356b1cc153108aaf27f3b72ce438af4aa218c0"
        },
        {
          "url": "https://github.com/python/cpython/commit/34d76b00dabde81a793bd06dd8ecb057838c4b38"
        },
        {
          "url": "https://github.com/python/cpython/commit/3f396ca9d7bbe2a50ea6b8c9b27c0082884d9f80"
        },
        {
          "url": "https://github.com/python/cpython/commit/4ed11d3cd288e6b90196a15c5a825a45d318fe47"
        },
        {
          "url": "https://github.com/python/cpython/commit/a35ca3be5842505dab74dc0b90b89cde0405017a"
        },
        {
          "url": "https://github.com/python/cpython/commit/f25509e78e8be6ea73c811ac2b8c928c28841b9f"
        },
        {
          "url": "https://github.com/python/cpython/issues/143925"
        },
        {
          "url": "https://github.com/python/cpython/pull/143926"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-15282.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/X66HL7SISGJT33J53OHXMZT4DFLMHVKF/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15282"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-15282"
        }
      ],
      "published": "2026-01-20T22:15:50+00:00",
      "updated": "2026-06-17T08:37:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-1632",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        404,
        476
      ],
      "description": "A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-1632"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-1632"
        },
        {
          "url": "https://github.com/Ekkosun/pocs/blob/main/bsdunzip-poc"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1632"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7454-1"
        },
        {
          "url": "https://vuldb.com/?ctiid.296619"
        },
        {
          "url": "https://vuldb.com/?id.296619"
        },
        {
          "url": "https://vuldb.com/?submit.496460"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1632"
        }
      ],
      "published": "2025-02-24T14:15:11+00:00",
      "updated": "2026-06-17T08:39:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-11.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-1795",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        116
      ],
      "description": "During an address list folding when a separating comma ends up on a folded line and that line is to be unicode-encoded then the separator itself is also unicode-encoded. Expected behavior is that the separating comma remains a plan comma. This can result in the address header being misinterpreted by some mail servers.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-1795"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-1795"
        },
        {
          "url": "https://github.com/python/cpython/commit/09fab93c3d857496c0bd162797fab816c311ee48"
        },
        {
          "url": "https://github.com/python/cpython/commit/70754d21c288535e86070ca7a6e90dcb670b8593"
        },
        {
          "url": "https://github.com/python/cpython/commit/9148b77e0af91cdacaa7fe3dfac09635c3fe9a74"
        },
        {
          "url": "https://github.com/python/cpython/commit/a4ef689ce670684ec132204b1cd03720c8e0a03d"
        },
        {
          "url": "https://github.com/python/cpython/commit/d4df3c55e4c5513947f907f24766b34d2ae8c090"
        },
        {
          "url": "https://github.com/python/cpython/issues/100884"
        },
        {
          "url": "https://github.com/python/cpython/pull/100885"
        },
        {
          "url": "https://github.com/python/cpython/pull/119099"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00013.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/MB62IZMEC3UM6SGHP5LET5JX2Y7H4ZUR/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1795"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7570-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1795"
        }
      ],
      "published": "2025-02-28T19:15:36+00:00",
      "updated": "2026-07-31T14:16:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-27113",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-27113"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/10"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/11"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/12"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/13"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/4"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/5"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/8"
        },
        {
          "url": "http://seclists.org/fulldisclosure/2025/Apr/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-27113"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/861"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27113"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20250306-0004/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7302-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-27113"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2025/02/18/2"
        }
      ],
      "published": "2025-02-18T23:15:10+00:00",
      "updated": "2026-06-17T09:03:03+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-28164",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        401,
        120
      ],
      "description": "Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-28164"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-28164"
        },
        {
          "url": "https://gist.github.com/kittener/506516f8c22178005b4379c8b2a7de20"
        },
        {
          "url": "https://github.com/pnggroup/libpng/issues/655"
        },
        {
          "url": "https://github.com/pnggroup/libpng/pull/657"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28164"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7993-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-28164"
        }
      ],
      "published": "2026-01-27T16:16:14+00:00",
      "updated": "2026-06-17T09:04:37+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.6.37-15.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-30258",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        754
      ],
      "description": "In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-30258"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-30258"
        },
        {
          "url": "https://dev.gnupg.org/T7527"
        },
        {
          "url": "https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30258"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7412-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7412-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-30258"
        }
      ],
      "published": "2025-03-19T20:15:20+00:00",
      "updated": "2026-06-17T09:08:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.3.3-5.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-3360",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-3360"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-3360"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2357754"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3647"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/work_items/3647"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/04/msg00024.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3360"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-3360"
        }
      ],
      "published": "2025-04-07T13:15:43+00:00",
      "updated": "2026-06-30T15:16:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-4516",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "There is an issue in CPython when using `bytes.decode(\"unicode_escape\", error=\"ignore|replace\")`. If you are not using the \"unicode_escape\" encoding or an error handler your usage is not affected. To work-around this issue you may stop using the error= handler and instead wrap the bytes.decode() call in a try-except catching the DecodeError.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-4516"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/05/16/4"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/05/19/1"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:23530"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-4516"
        },
        {
          "url": "https://bugzilla.redhat.com/2294682"
        },
        {
          "url": "https://bugzilla.redhat.com/2321440"
        },
        {
          "url": "https://bugzilla.redhat.com/2325776"
        },
        {
          "url": "https://bugzilla.redhat.com/2343237"
        },
        {
          "url": "https://bugzilla.redhat.com/2366509"
        },
        {
          "url": "https://bugzilla.redhat.com/2370010"
        },
        {
          "url": "https://bugzilla.redhat.com/2370014"
        },
        {
          "url": "https://bugzilla.redhat.com/2370016"
        },
        {
          "url": "https://bugzilla.redhat.com/2372426"
        },
        {
          "url": "https://bugzilla.redhat.com/2373234"
        },
        {
          "url": "https://bugzilla.redhat.com/2402342"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294682"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2321440"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2325776"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2343237"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2366509"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370010"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370014"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370016"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2372426"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2373234"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402342"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11168"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5642"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-9287"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-0938"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4138"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4330"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4435"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4516"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4517"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6069"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8291"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2025-23530.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:23530"
        },
        {
          "url": "https://github.com/python/cpython/commit/4398b788ffc1f954a2c552da285477d42a571292"
        },
        {
          "url": "https://github.com/python/cpython/commit/5646648678295a44aa82636c6e92826651baf33a"
        },
        {
          "url": "https://github.com/python/cpython/commit/6279eb8c076d89d3739a6edb393e43c7929b429d"
        },
        {
          "url": "https://github.com/python/cpython/commit/69b4387f78f413e8c47572a85b3478c47eba8142"
        },
        {
          "url": "https://github.com/python/cpython/commit/73b3040f592436385007918887b7e2132aa8431f"
        },
        {
          "url": "https://github.com/python/cpython/commit/8d35fd1b34935221aff23a1ab69a429dd156be77"
        },
        {
          "url": "https://github.com/python/cpython/commit/9f69a58623bd01349a18ba0c7a9cb1dad6a51e8e"
        },
        {
          "url": "https://github.com/python/cpython/commit/9f69a58623bd01349a18ba0c7a9cb1dad6a51e8e%20%28main%29"
        },
        {
          "url": "https://github.com/python/cpython/commit/ab9893c40609935e0d40a6d2a7307ea51aec598b"
        },
        {
          "url": "https://github.com/python/cpython/issues/133767"
        },
        {
          "url": "https://github.com/python/cpython/pull/129648"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-4516.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-23530.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L75IPBBTSCYEF56I2M4KIW353BB3AY74/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4516"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7570-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-4516"
        }
      ],
      "published": "2025-05-15T14:15:31+00:00",
      "updated": "2026-07-31T14:16:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-47273",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        22
      ],
      "description": "setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.",
      "recommendation": "Upgrade setuptools to version 78.1.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-47273"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:10407"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2025:13578"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-47273"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2025-47273"
        },
        {
          "url": "https://bugzilla.redhat.com/2366982"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2366982"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-47273"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2025-13578.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2025:10407"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2025-49.yaml"
        },
        {
          "url": "https://github.com/pypa/setuptools"
        },
        {
          "url": "https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88"
        },
        {
          "url": "https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b"
        },
        {
          "url": "https://github.com/pypa/setuptools/issues/4946"
        },
        {
          "url": "https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2025-47273.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2025-9940.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00035.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47273"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7544-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8010-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-47273"
        }
      ],
      "published": "2025-05-17T16:15:19+00:00",
      "updated": "2026-06-17T09:27:38+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/setuptools@70.3.0",
          "versions": [
            {
              "version": "70.3.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:pypi/setuptools@70.3.0"
        }
      ]
    },
    {
      "id": "CVE-2025-50181",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        601
      ],
      "description": "urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-50181"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-50181"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2025-50181"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/f05b1329126d5be6de501f9d1e3e36738bc08857"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/2.5.0"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-pq67-6m6q-mj2v"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-50181"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7599-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7599-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-50181"
        }
      ],
      "published": "2025-06-19T01:15:24+00:00",
      "updated": "2026-06-17T09:34:48+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "21.3.1-2.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-50182",
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        601
      ],
      "description": "urllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does not control redirects in browsers and Node.js. urllib3 supports being used in a Pyodide runtime utilizing the JavaScript Fetch API or falling back on XMLHttpRequest. This means Python libraries can be used to make HTTP requests from a browser or Node.js. Additionally, urllib3 provides a mechanism to control redirects, but the retries and redirect parameters are ignored with Pyodide; the runtime itself determines redirect behavior. This issue has been patched in version 2.5.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-50182"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-50182"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2025-50182"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/7eb4a2aafe49a279c29b6d1f0ed0f42e9736194f"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/2.5.0"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-48p4-8xcf-vxj5"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-50182"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7599-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-50182"
        }
      ],
      "published": "2025-06-19T02:15:17+00:00",
      "updated": "2026-06-17T09:34:48+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "21.3.1-2.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5915",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.6,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5915"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5915"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370865"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2599"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5915"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7601-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5915"
        }
      ],
      "published": "2025-06-09T20:15:26+00:00",
      "updated": "2026-09-01T13:17:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-11.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5916",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive. This bug affects libarchive versions prior to 3.8.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5916"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5916"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370872"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2568"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2568/commits/bce70c4c26864df2a8d6953e7db6e4b156253508"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5916"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7601-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5916"
        }
      ],
      "published": "2025-06-09T20:15:27+00:00",
      "updated": "2026-09-01T13:17:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-11.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5917",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation. This bug affects libarchive versions prior to 3.8.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5917"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5917"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370874"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2588"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5917"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7601-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5917"
        }
      ],
      "published": "2025-06-09T20:15:27+00:00",
      "updated": "2026-09-01T13:17:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-11.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-5918",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        125
      ],
      "description": "A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-5918"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-5918"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370877"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2584"
        },
        {
          "url": "https://github.com/libarchive/libarchive/releases/tag/v3.8.0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5918"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-5918"
        }
      ],
      "published": "2025-06-09T20:15:27+00:00",
      "updated": "2026-09-01T13:17:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-11.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-60753",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        400,
        835
      ],
      "description": "An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-60753"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-60753"
        },
        {
          "url": "https://github.com/Papya-j/CVE/tree/main/CVE-2025-60753"
        },
        {
          "url": "https://github.com/libarchive/libarchive/issues/2725"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-60753"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8147-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-60753"
        }
      ],
      "published": "2025-11-05T16:15:40+00:00",
      "updated": "2026-06-17T09:50:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-11.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-64118",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        362,
        367
      ],
      "description": "node-tar is a Tar for Node.js. In 7.5.1, using .t (aka .list) with { sync: true } to read tar entry contents returns uninitialized memory contents if tar file was changed on disk to a smaller size while being read. This vulnerability is fixed in 7.5.2.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-64118"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-64118"
        },
        {
          "url": "https://github.com/isaacs/node-tar"
        },
        {
          "url": "https://github.com/isaacs/node-tar/commit/5330eb04bc43014f216e5c271b40d5c00d45224d"
        },
        {
          "url": "https://github.com/isaacs/node-tar/commit/5e1a8e638600d3c3a2969b4de6a6ec44fa8d74c9"
        },
        {
          "url": "https://github.com/isaacs/node-tar/issues/445"
        },
        {
          "url": "https://github.com/isaacs/node-tar/pull/446"
        },
        {
          "url": "https://github.com/isaacs/node-tar/security/advisories/GHSA-29xp-372q-xqph"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-64118"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-64118"
        }
      ],
      "published": "2025-10-30T18:15:33+00:00",
      "updated": "2026-10-07T22:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.34-13.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.34-13.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/tar@1.34-13.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-64505",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to version 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_do_quantize function when processing PNG files with malformed palette indices. The vulnerability occurs when palette_lookup array bounds are not validated against externally-supplied image data, allowing an attacker to craft a PNG file with out-of-range palette indices that trigger out-of-bounds memory access. This issue has been patched in version 1.6.51.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-64505"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-64505"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/6a528eb5fd0dd7f6de1c39d30de0e41473431c37"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/6a528eb5fd0dd7f6de1c39d30de0e41473431c37%20%28v1.6.51%29"
        },
        {
          "url": "https://github.com/pnggroup/libpng/pull/748"
        },
        {
          "url": "https://github.com/pnggroup/libpng/security/advisories/GHSA-4952-h5wq-4m42"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-64505"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7924-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8081-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-64505"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2025/11/22/1"
        }
      ],
      "published": "2025-11-25T00:15:47+00:00",
      "updated": "2026-06-17T09:54:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.6.37-15.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-64506",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_write_image_8bit function when processing 8-bit images through the simplified write API with convert_to_8bit enabled. The vulnerability affects 8-bit grayscale+alpha, RGB/RGBA, and images with incomplete row data. A conditional guard incorrectly allows 8-bit input to enter code expecting 16-bit input, causing reads up to 2 bytes beyond allocated buffer boundaries. This issue has been patched in version 1.6.51.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-64506"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-64506"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/2bd84c019c300b78e811743fbcddb67c9d9bf821"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/2bd84c019c300b78e811743fbcddb67c9d9bf821%20%28v1.6.51%29"
        },
        {
          "url": "https://github.com/pnggroup/libpng/pull/749"
        },
        {
          "url": "https://github.com/pnggroup/libpng/security/advisories/GHSA-qpr4-xm66-hww6"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-64506"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7924-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-64506"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2025/11/22/1"
        }
      ],
      "published": "2025-11-25T00:15:47+00:00",
      "updated": "2026-06-17T09:54:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.6.37-15.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-66382",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        407
      ],
      "description": "In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-66382"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/12/02/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-66382"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/issues/1076"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-66382"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-66382"
        }
      ],
      "published": "2025-11-28T07:15:57+00:00",
      "updated": "2026-06-17T09:56:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-68972",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        347
      ],
      "description": "In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-68972"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-68972"
        },
        {
          "url": "https://github.com/advisories/GHSA-w789-3q45-984r"
        },
        {
          "url": "https://gpg.fail/formfeed"
        },
        {
          "url": "https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i"
        },
        {
          "url": "https://news.ycombinator.com/item?id=46404339"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68972"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-68972"
        }
      ],
      "published": "2025-12-27T23:15:40+00:00",
      "updated": "2026-06-17T09:59:55+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.3.3-5.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-7039",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        22
      ],
      "description": "A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-7039"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-7039"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2392423"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3716"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-7039"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7942-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-7039"
        }
      ],
      "published": "2025-09-03T02:15:38+00:00",
      "updated": "2026-06-17T10:04:08+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-70873",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        244
      ],
      "description": "An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-70873"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-70873"
        },
        {
          "url": "https://gist.github.com/cnwangjihe/f496393f30f5ecec5b18c8f5ab072054"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-70873"
        },
        {
          "url": "https://sqlite.org/forum/forumpost/761eac3c82"
        },
        {
          "url": "https://sqlite.org/src/info/3d459f1fb1bd1b5e"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-70873"
        }
      ],
      "published": "2026-03-12T19:16:15+00:00",
      "updated": "2026-06-17T10:03:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.34.1-11.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2025-9232",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Issue summary: An application using the OpenSSL HTTP client API functions may\ntrigger an out-of-bounds read if the 'no_proxy' environment variable is set and\nthe host portion of the authority component of the HTTP URL is an IPv6 address.\n\nImpact summary: An out-of-bounds read can trigger a crash which leads to\nDenial of Service for an application.\n\nThe OpenSSL HTTP client API functions can be used directly by applications\nbut they are also used by the OCSP client functions and CMP (Certificate\nManagement Protocol) client implementation in OpenSSL. However the URLs used\nby these implementations are unlikely to be controlled by an attacker.\n\nIn this vulnerable code the out of bounds read can only trigger a crash.\nFurthermore the vulnerability requires an attacker-controlled URL to be\npassed from an application to the OpenSSL function and the user has to have\na 'no_proxy' environment variable set. For the aforementioned reasons the\nissue was assessed as Low severity.\n\nThe vulnerable code was introduced in the following patch releases:\n3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0.\n\nThe FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this\nissue, as the HTTP client implementation is outside the OpenSSL FIPS module\nboundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2025-9232"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/09/30/5"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-9232"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-089022.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-485750.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-585531.html"
        },
        {
          "url": "https://github.com/advisories/GHSA-76r2-c3cg-f5r9"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2b4ec20e47959170422922eaff25346d362dcb35"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/654dc11d23468a74fc8ea4672b702dd3feb7be4b"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7cf21a30513c9e43c4bc3836c237cf086e194af3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/89e790ac431125a4849992858490bed6b225eadf"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/bbf38c034cdabd0a13330abcc4855c866f53d2e0"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-9232"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20250930.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7786-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7894-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-9232"
        }
      ],
      "published": "2025-09-30T14:15:41+00:00",
      "updated": "2026-07-14T13:18:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0672",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        93
      ],
      "description": "When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0672"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0672"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/62700107418eb2cca3fc88da036a243ea975f172"
        },
        {
          "url": "https://github.com/python/cpython/commit/712452e6f1d4b9f7f8c4c92ebfcaac1705faa440"
        },
        {
          "url": "https://github.com/python/cpython/commit/7852d72b653fea0199acf5fc2a84f6f8b84eba8d"
        },
        {
          "url": "https://github.com/python/cpython/commit/918387e4912d12ffc166c8f2a38df92b6ec756ca"
        },
        {
          "url": "https://github.com/python/cpython/commit/95746b3a13a985787ef53b977129041971ed7f70"
        },
        {
          "url": "https://github.com/python/cpython/commit/b1869ff648bbee0717221d09e6deff46617f3e85"
        },
        {
          "url": "https://github.com/python/cpython/issues/143919"
        },
        {
          "url": "https://github.com/python/cpython/pull/143920"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-0672.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/6VFLQQEIX673KXKFUZXCUNE5AZOGZ45M/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0672"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8018-3"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0672"
        }
      ],
      "published": "2026-01-20T22:15:52+00:00",
      "updated": "2026-06-17T10:11:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0799",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.7,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125,
        129,
        787
      ],
      "description": "In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value.  In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.",
      "recommendation": "Upgrade libpcap to version 14:1.10.0-4.el9_8.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0799"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74441"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0799"
        },
        {
          "url": "https://bugzilla.redhat.com/2529093"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2529093"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0799"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-74441.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:74441"
        },
        {
          "url": "https://github.com/the-tcpdump-group/libpcap/commit/48e8960a7108e9e828f9d7bdc7e97bdab841aec7"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-0799.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-76045.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0799"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8824-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0799"
        }
      ],
      "published": "2026-09-05T19:16:55+00:00",
      "updated": "2026-09-08T19:20:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14",
          "versions": [
            {
              "version": "14:1.10.0-4.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-0864",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "cwes": [
        74
      ],
      "description": "When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0864"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0864"
        },
        {
          "url": "https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528"
        },
        {
          "url": "https://github.com/python/cpython/commit/12dcbd74d3563016a8cb8c47e4898889f34f74dd"
        },
        {
          "url": "https://github.com/python/cpython/commit/274de100bbf4345bd0c23ef5b446722e9e636908"
        },
        {
          "url": "https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f"
        },
        {
          "url": "https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98"
        },
        {
          "url": "https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8"
        },
        {
          "url": "https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6"
        },
        {
          "url": "https://github.com/python/cpython/issues/143927"
        },
        {
          "url": "https://github.com/python/cpython/pull/151559"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0864"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0864"
        }
      ],
      "published": "2026-06-23T18:17:41+00:00",
      "updated": "2026-08-18T17:52:03+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-0988",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0988"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7461"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0988"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429886"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3851"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0988"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7971-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0988"
        }
      ],
      "published": "2026-01-21T12:15:55+00:00",
      "updated": "2026-06-17T10:11:43+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0989",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0989"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0989"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429933"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/998"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/374"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0989"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7974-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0989"
        }
      ],
      "published": "2026-01-15T15:15:52+00:00",
      "updated": "2026-09-01T13:18:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0990",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0990"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0990"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429959"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1018"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0990"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7974-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0990"
        }
      ],
      "published": "2026-01-15T15:15:52+00:00",
      "updated": "2026-09-01T12:17:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-0992",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-0992"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-0992"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429975"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1019"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0992"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-7974-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-0992"
        }
      ],
      "published": "2026-01-15T15:15:52+00:00",
      "updated": "2026-09-01T13:18:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-102010",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H"
        }
      ],
      "cwes": [
        825
      ],
      "description": "A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-102010"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73642"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74569"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-102010"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2478395"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-102010"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-102010"
        }
      ],
      "published": "2026-09-28T19:16:48+00:00",
      "updated": "2026-10-02T03:16:38+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-102633",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-102633"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-102633"
        },
        {
          "url": "https://github.com/libexpat/libexpat"
        },
        {
          "url": "https://github.com/libexpat/libexpat/blob/R_2_8_5/expat/lib/xmlparse.c#L1003"
        },
        {
          "url": "https://github.com/libexpat/libexpat/commit/209801d7fbaf07ab74bae8cb32dd2ab9e5846118"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1392"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-102633"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-102633"
        },
        {
          "url": "https://www.vulncheck.com/advisories/libexpat-2.7.2-through-2.8.5-integer-overflow-in-expat-realloc"
        }
      ],
      "published": "2026-09-29T17:17:06+00:00",
      "updated": "2026-09-29T21:32:59+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-103111",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.6,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L"
        }
      ],
      "cwes": [
        787
      ],
      "description": "PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-103111"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-103111"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/10/msg00008.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-103111"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-103111"
        }
      ],
      "published": "2026-09-30T05:16:45+00:00",
      "updated": "2026-10-04T00:16:35+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-103242",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared with the wrong header type, causing hex2binv() to allocate a one-byte buffer and then write the tag's attacker-controlled, hex-decoded content \u2014 of attacker-chosen length \u2014 past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-103242"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-103242"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2543866"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-103242"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-103242"
        }
      ],
      "published": "2026-09-30T12:17:12+00:00",
      "updated": "2026-09-30T17:16:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-105712",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.6,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L"
        }
      ],
      "cwes": [
        61
      ],
      "description": "gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-105712"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-105712"
        },
        {
          "url": "https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-105712"
        },
        {
          "url": "https://static.dev.gnupg.org/T8159.html"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-105712"
        }
      ],
      "published": "2026-10-05T19:17:19+00:00",
      "updated": "2026-10-06T16:00:36+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.3.3-5.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-107161",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-of-bounds write whose size depends on attacker-controlled input. A malicious or on-path DIGEST-MD5 (or HTTP Digest) server can trigger this flaw in a connecting client by supplying a crafted challenge field, such as realm or nonce, most likely resulting in a crash of the client application.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107161"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-107161"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460420"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107161"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-107161"
        }
      ],
      "published": "2026-10-07T20:17:10+00:00",
      "updated": "2026-10-09T02:17:02+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-22.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.1.27-22.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-22.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-22.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-22.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-22.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-22.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-22.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-22.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-22.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-22.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-22.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-22.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-22.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-22.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-22.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-22.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-107708",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        476
      ],
      "description": "MIT krb5 through 1.22.2 contains a NULL pointer dereference vulnerability in the KDC's get_pac_princ_with_realm() that returns success while leaving the client principal NULL on malformed names. A malicious or compromised cross-realm trusted KDC can send an S4U2Proxy request with a PAC carrying a malformed client name to crash krb5kdc and deny authentication.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107708"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-107708"
        },
        {
          "url": "https://github.com/krb5/krb5"
        },
        {
          "url": "https://github.com/krb5/krb5/blob/krb5-1.22.2-final/src/kdc/kdc_util.c#L639-L676"
        },
        {
          "url": "https://github.com/krb5/krb5/commit/a88a18cafa1040a0c4f9c8d08288fc98831ec86d"
        },
        {
          "url": "https://github.com/krb5/krb5/commit/f6e2c397ceda6467ebbaab8ed66d4895c9f1d6a7"
        },
        {
          "url": "https://github.com/krb5/krb5/pull/1510"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107708"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-107708"
        },
        {
          "url": "https://www.vulncheck.com/advisories/mit-krb5-through-1.22.2-kdc-null-pointer-dereference-via-s4u2proxy-pac"
        }
      ],
      "published": "2026-10-08T21:17:52+00:00",
      "updated": "2026-10-08T21:33:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/krb5-pkinit@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/krb5-workstation@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libkadm5@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/krb5-pkinit@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/krb5-workstation@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libkadm5@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-107778",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        476
      ],
      "description": "MIT Kerberos 5 (krb5) through 1.22.2 contains a NULL pointer dereference in make_cred_list() in rd_cred.c that allows authenticated Kerberos clients to crash services by sending mismatched KRB-CRED arrays. Attackers can send forwarded credentials with more tickets than ticket_info entries through gss_accept_sec_context() to crash GSS-API acceptor services, causing denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-107778"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-107778"
        },
        {
          "url": "https://github.com/krb5/krb5"
        },
        {
          "url": "https://github.com/krb5/krb5/blob/krb5-1.22.2-final/src/lib/krb5/krb/rd_cred.c#L77-L112"
        },
        {
          "url": "https://github.com/krb5/krb5/commit/48afa9abb89ab2176bb20624d87d010b9984fc08"
        },
        {
          "url": "https://github.com/krb5/krb5/commit/62196e2b269159a5465f5b8d0ed7cf6f29c3282a"
        },
        {
          "url": "https://github.com/krb5/krb5/pull/1511"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107778"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-107778"
        },
        {
          "url": "https://www.vulncheck.com/advisories/mit-krb5-through-1.22.2-null-pointer-dereference-via-krb5-rd-cred"
        }
      ],
      "published": "2026-10-08T21:17:52+00:00",
      "updated": "2026-10-08T21:33:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/krb5-pkinit@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/krb5-workstation@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libkadm5@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/krb5-pkinit@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/krb5-workstation@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libkadm5@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-11850",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        191
      ],
      "description": "An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11850"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:25520"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11850"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2459970"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11850"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8585-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11850"
        }
      ],
      "published": "2026-06-11T10:16:21+00:00",
      "updated": "2026-08-31T18:17:12+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/krb5-pkinit@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/krb5-workstation@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libkadm5@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-10.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/krb5-pkinit@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/krb5-workstation@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libkadm5@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-11856",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        294
      ],
      "description": "Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Authorization:` header field meant for `hostA`,\nto `hostB`.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11856"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69125"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11856"
        },
        {
          "url": "https://bugzilla.redhat.com/2496759"
        },
        {
          "url": "https://bugzilla.redhat.com/2496760"
        },
        {
          "url": "https://bugzilla.redhat.com/2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/2496765"
        },
        {
          "url": "https://bugzilla.redhat.com/2496767"
        },
        {
          "url": "https://bugzilla.redhat.com/2496771"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496759"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496760"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496765"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496767"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496771"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-11856.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-11856.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-11856.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-11856"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8458"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8924"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8926"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8932"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9079"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-69125.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69125"
        },
        {
          "url": "https://github.com/advisories/GHSA-9crq-qh8v-6xmm"
        },
        {
          "url": "https://hackerone.com/reports/3793260"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-11856.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-69125.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11856"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8651-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11856"
        }
      ],
      "published": "2026-07-03T07:16:23+00:00",
      "updated": "2026-09-15T07:16:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-11972",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        252,
        606,
        770
      ],
      "description": "When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-11972"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11972"
        },
        {
          "url": "https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9"
        },
        {
          "url": "https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365"
        },
        {
          "url": "https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21"
        },
        {
          "url": "https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec"
        },
        {
          "url": "https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192"
        },
        {
          "url": "https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896"
        },
        {
          "url": "https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438"
        },
        {
          "url": "https://github.com/python/cpython/issues/151981"
        },
        {
          "url": "https://github.com/python/cpython/pull/151982"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11972"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11972"
        }
      ],
      "published": "2026-06-23T23:16:49+00:00",
      "updated": "2026-08-13T01:16:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-12345",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "cwes": [
        59
      ],
      "description": "The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-12345"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/09/29/40"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-12345"
        },
        {
          "url": "https://github.com/python/cpython/commit/06ef3d43fdaf4da97af12fa694b4886092c4b970"
        },
        {
          "url": "https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420"
        },
        {
          "url": "https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d"
        },
        {
          "url": "https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993"
        },
        {
          "url": "https://github.com/python/cpython/issues/157579"
        },
        {
          "url": "https://github.com/python/cpython/pull/157580"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12345"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-12345"
        }
      ],
      "published": "2026-09-29T18:17:14+00:00",
      "updated": "2026-10-03T01:17:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-12610",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        825
      ],
      "description": "A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-12610"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-12610"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490288"
        },
        {
          "url": "https://github.com/SSSD/sssd/issues/8796"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12610"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8672-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-12610"
        }
      ],
      "published": "2026-06-30T10:16:34+00:00",
      "updated": "2026-08-31T19:16:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pam@1.5.1-28.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.5.1-28.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/pam@1.5.1-28.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/pam@1.5.1-28.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/pam@1.5.1-28.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-13346",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L"
        }
      ],
      "cwes": [
        36
      ],
      "description": "pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.\n\n\n\n\nThis vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-13346"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/29/7"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-13346"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-13346"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2026-3721.yaml"
        },
        {
          "url": "https://github.com/pypa/pip"
        },
        {
          "url": "https://github.com/pypa/pip/commit/10dfb6b9005484578b386f64b9f36982e3dc6679"
        },
        {
          "url": "https://github.com/pypa/pip/pull/14110"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13346"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13346"
        }
      ],
      "published": "2026-07-29T19:16:44+00:00",
      "updated": "2026-08-20T13:17:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "21.3.1-2.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-13595",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-13595"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26573"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-13595"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494101"
        },
        {
          "url": "https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13595"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8702-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13595"
        }
      ],
      "published": "2026-06-29T09:16:28+00:00",
      "updated": "2026-08-31T18:17:13+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-14456",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes\nvalid QUIC Initial packets for unknown destination connection IDs, it\ncan allocate and queue new incoming channels without enforcing any limit.\n\nImpact summary: A remote peer that can make many Initial packets reach the\nserver listener faster than the application accepts connections, can cause the\nmemory allocated to store the per-channel state to grow without any limits,\npotentially making the QUIC listener unavailable and causing Denial of Service.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The function that handles inbound QUIC packets uses\nConnection-Id from the packet header to find an existing connection\n(QUIC channel). If no existing connection is found and the packet\ntype is INITIAL, the function treats the packet as a new connection. It\nallocates a new channel object and inserts it into a queue where it\nwaits to be accepted by the local application with SSL_accept(3ossl).\nThe memory occupied by these initial channel objects may grow\nwithout bounds if the application is not able to call SSL_accept()\nfrequently enough to serve these inbound connection requests.\n\nThe issue is present since OpenSSL 3.5 when the QUIC server implementation\nwas added.\n\nThe fix introduces a limit for pending connections. The default limit is set\nto 256 pending connections (waiting to be accepted by the local application).\nApplications may change the default by calling SSL_set_value_uint(3ossl).\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.",
      "recommendation": "Upgrade openssl to version 1:3.5.8-1.el9_8; Upgrade openssl-libs to version 1:3.5.8-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-14456"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/08/13/4"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67165"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-14456"
        },
        {
          "url": "https://bugzilla.redhat.com/2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/2517570"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517570"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14456"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14457"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18798"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54874"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63072"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63073"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63074"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67165.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67165"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/08e7756c3900bcfd77a720e7b74e27d6e4ed01a9"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4084152e040329ca0194c4c1750b9b46d00a5b6b"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-14456.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67165-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14456"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260813.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-14456"
        }
      ],
      "published": "2026-08-13T15:19:31+00:00",
      "updated": "2026-08-28T19:46:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-14457",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs)\nenabled, and only the private key (with no associated certificate) configured locally,\na NULL pointer dereference may occur when the remote peer solicits raw public keys and\nalso sends the typically omitted \"signature_algorithms_cert\" TLS extension.\n\nImpact summary: The impact is limited to a possible Denial of Service as a result of\nan application abort, no data disclosure or remote command execution are possible.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: While a passing comment in sample code in the documentation suggests\nthat key-only RPK configurations are supported, the best-practice RPK configuration\nis to always configure a corresponding certificate (possibly self-signed or\nsigned by any convenient CA).\n\nWhen the private key is configured along with a matching certificate, the\n\"signature_algorithms_cert\" extension is handled reliably even without the\nfix, and peer clients or servers that don't support raw public keys may be\nable to complete a TLS connection by pinning or verifying the corresponding\ncertificate or its public key.\n\nDeployments that prefer to configure just a private key with no certificate\nneed to upgrade to an updated release as noted below.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the SSL protocol implementation\nis outside the OpenSSL FIPS module boundary.",
      "recommendation": "Upgrade openssl to version 1:3.5.8-1.el9_8; Upgrade openssl-libs to version 1:3.5.8-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-14457"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67165"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-14457"
        },
        {
          "url": "https://bugzilla.redhat.com/2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/2517570"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517570"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14456"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14457"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18798"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54874"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63072"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63073"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63074"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67165.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67165"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/1e8c398db67404babd3e5af999bb6bd86f720c76"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/581aaa0f0a35d214740f0fe1f5283ec41f1212e1"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d0af20478688a6aa2f59d61caa3f82136b181d7f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/dad836b071da6579510c968615848ba03cac593b"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-14457.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67165-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14457"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260825.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-14457"
        }
      ],
      "published": "2026-08-25T13:17:49+00:00",
      "updated": "2026-09-11T21:14:35+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-1484",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory writes outside the allocated buffer. Applications that process untrusted or extremely large Base64 input using GLib may crash or behave unpredictably.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1484"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1484"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1484"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433259"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-quby27cpefwz.toml"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3870"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1484"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8017-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1484"
        }
      ],
      "published": "2026-01-27T14:15:56+00:00",
      "updated": "2026-06-17T10:15:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-1485",
      "ratings": [
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        124
      ],
      "description": "A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1485"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1485"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1485"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433325"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-hui7k8rsmbsl.toml"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3871"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1485"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8017-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1485"
        }
      ],
      "published": "2026-01-27T14:15:56+00:00",
      "updated": "2026-06-17T10:15:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-1489",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1489"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1489"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1489"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433348"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-h6zf92f0298p.toml"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3872"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1489"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8017-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1489"
        }
      ],
      "published": "2026-01-27T15:15:57+00:00",
      "updated": "2026-06-17T10:15:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-1502",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        93
      ],
      "description": "CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1502"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/11/4"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1502"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69"
        },
        {
          "url": "https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53"
        },
        {
          "url": "https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e"
        },
        {
          "url": "https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd"
        },
        {
          "url": "https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed"
        },
        {
          "url": "https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec"
        },
        {
          "url": "https://github.com/python/cpython/issues/146211"
        },
        {
          "url": "https://github.com/python/cpython/pull/146212"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-1502.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1502"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1502"
        }
      ],
      "published": "2026-04-10T18:16:40+00:00",
      "updated": "2026-08-13T01:16:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-15028",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        805,
        122
      ],
      "description": "A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of service, making the system unavailable, or potentially allow for arbitrary code execution, giving the attacker control over the affected system.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-15028"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38279"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69553"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:79357"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15028"
        },
        {
          "url": "https://bugzilla.redhat.com/2497970"
        },
        {
          "url": "https://bugzilla.redhat.com/2505492"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497970"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2505492"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15028"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-16517"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-69553.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69553"
        },
        {
          "url": "https://github.com/libarchive/libarchive/issues/3251"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/3253"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-15028.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-69553.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15028"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8581-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-15028"
        }
      ],
      "published": "2026-07-10T10:16:23+00:00",
      "updated": "2026-10-09T02:17:02+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-11.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-15059",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        22,
        59
      ],
      "description": "Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-15059"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15059"
        },
        {
          "url": "https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15059"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8626-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-15059"
        }
      ],
      "published": "2026-08-10T14:17:20+00:00",
      "updated": "2026-09-01T20:54:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "252-67.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "252-67.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "252-67.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "252-67.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-15146",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget\u2019s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-15146"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15146"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b"
        },
        {
          "url": "https://kb.cert.org/vuls/id/564823"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15146"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8572-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-15146"
        },
        {
          "url": "https://www.kb.cert.org/vuls/id/564823"
        }
      ],
      "published": "2026-07-10T19:17:20+00:00",
      "updated": "2026-07-15T19:16:57+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.21.1-11.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-11.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/wget@1.21.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-16599",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        606
      ],
      "description": "GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a crafted OPIE challenge with a sequence number near INT_MAX, causing wget to perform up to approximately 2.1 billion MD5 computations and suspend for some time. The --timeout option does not mitigate this because it applies only to network I/O, not CPU computation.\n\n\nThis issue was fixed in commit e9697d98e7249b0f68a6be040a4f3dcc5bc101fa",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-16599"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16599"
        },
        {
          "url": "https://cert.pl/en/posts/2026/08/CVE-2026-16599"
        },
        {
          "url": "https://gitlab.com/gnuwget/wget"
        },
        {
          "url": "https://gitlab.com/gnuwget/wget/-/commit/e9697d98e7249b0f68a6be040a4f3dcc5bc101fa"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16599"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-16599"
        }
      ],
      "published": "2026-08-25T15:16:30+00:00",
      "updated": "2026-08-28T15:26:19+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.21.1-11.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-11.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/wget@1.21.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-1757",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        401
      ],
      "description": "A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-1757"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1757"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2435940"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1009"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1757"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8460-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1757"
        }
      ],
      "published": "2026-02-02T13:15:58+00:00",
      "updated": "2026-09-01T12:17:36+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-18238",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "cwes": [
        126,
        1288
      ],
      "description": "The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers.  A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end of the buffer as if it was a part of the captured packet.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18238"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18238"
        },
        {
          "url": "https://github.com/the-tcpdump-group/libpcap/commit/b9590d482986d64673712460aae1d48d11fa0473"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18238"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18238"
        }
      ],
      "published": "2026-09-05T19:16:55+00:00",
      "updated": "2026-09-08T19:20:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14",
          "versions": [
            {
              "version": "14:1.10.0-4.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-18313",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        401
      ],
      "description": "rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it leaks memory even under normal use.  A malicious client can cause the server to leak memory substantially faster.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18313"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18313"
        },
        {
          "url": "https://github.com/the-tcpdump-group/libpcap/commit/f9775af1a0ec76db60c7213241e6b48f1be10ac7"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18313"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18313"
        }
      ],
      "published": "2026-09-05T19:16:55+00:00",
      "updated": "2026-09-08T19:20:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14",
          "versions": [
            {
              "version": "14:1.10.0-4.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-18374",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.",
      "recommendation": "Upgrade glibc to version 2.34-283.el9_8; Upgrade glibc-common to version 2.34-283.el9_8; Upgrade glibc-minimal-langpack to version 2.34-283.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18374"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/08/27/6"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18374"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18374"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34574"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0015"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18374"
        }
      ],
      "published": "2026-08-27T20:17:03+00:00",
      "updated": "2026-09-03T16:43:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-18503",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        1176
      ],
      "description": "Attacker-controlled CSV samples can trigger super-linear \nregular-expression work during dialect sniffing and consume significant \nCPU when applications pass unbounded input to csv.Sniffer.sniff().",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18503"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18503"
        },
        {
          "url": "https://github.com/python/cpython/commit/063d4555c94ef412c731527dbf30193327f2ee82"
        },
        {
          "url": "https://github.com/python/cpython/commit/476fb09cdb0d73e645849d98c610e7e5697ce7c9"
        },
        {
          "url": "https://github.com/python/cpython/commit/89f29c760c02774b099ddd6863268eb13fa3946a"
        },
        {
          "url": "https://github.com/python/cpython/commit/b09a67a20c464f8288c9f9a6b9c7082a74560024"
        },
        {
          "url": "https://github.com/python/cpython/commit/b30c7fa9edd921a118f286e9f90f560777fa693b"
        },
        {
          "url": "https://github.com/python/cpython/commit/fd78b565d7c326f96ae903ab945b47f35d829cf4"
        },
        {
          "url": "https://github.com/python/cpython/issues/98820"
        },
        {
          "url": "https://github.com/python/cpython/pull/153694"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18503"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18503"
        }
      ],
      "published": "2026-08-10T14:17:21+00:00",
      "updated": "2026-08-18T15:04:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-18739",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18739"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56984"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18739"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2510737"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18739"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18739"
        }
      ],
      "published": "2026-08-04T06:16:30+00:00",
      "updated": "2026-08-31T18:17:14+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.18-8.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-18743",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        131
      ],
      "description": "A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `poptConfigFileToString` function reallocates memory for buffers. Successful exploitation could result in heap metadata corruption, potentially causing the affected process to become unavailable (denial of service).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18743"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56984"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18743"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2510809"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18743"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18743"
        }
      ],
      "published": "2026-09-01T02:16:57+00:00",
      "updated": "2026-09-08T23:17:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.18-8.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-18798",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        415
      ],
      "description": "Issue summary: QUIC server may double free QRX (QUIC record layer RX) object\nwhen channel creation fails for initial packet.\n\nImpact summary: Double free leads to heap corruption, which typically results in \ntermination of QUIC server process, leading to Denial of Service. There is so\nfar no evidence that this double free is exploitable for remote code execution,\nthus it is considered highly improbable.\n\nCWE: CWE-415: Double Free\n\nDescription: In order to validate initial packet, OpenSSL QUIC stack default\npacket handler (port_default_packet_handler()) creates a so-called QRX object.\nIf the initial packet validates successfully with QRX object, the default packet\nhandler proceeds to channel (connection object) creation. The QRX object used\nfor packet validation is passed to port_bind_channel(), so it becomes part of\nthe newly created connection. If port_bind_channel() fails, then it also frees\nthe QRX object. Once port_bind_channel() returns, the port_default_packet_handler()\ndetects the failure and proceeds to the error branch, where the same QRX object is\nfreed for the second time.\n\nThe failure in port_bind_channel() function can be induced with a relatively\nlow effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet\ncarries DCID (destination connection ID) which is shorter than 8 bytes, then\nport_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid()\ndetects that the DCID has invalid length.\n\nFIPS impact: no\nThe FIPS module is not affected, as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.",
      "recommendation": "Upgrade openssl to version 1:3.5.8-1.el9_8; Upgrade openssl-libs to version 1:3.5.8-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18798"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67165"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18798"
        },
        {
          "url": "https://bugzilla.redhat.com/2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/2517570"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517570"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14456"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14457"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18798"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54874"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63072"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63073"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63074"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67165.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67165"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/70cebd74d3592f5272945501b58a60374c4e13af"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/967582d5037f01a26b6d19beae19af62a1b15c3c"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a14a1deac403522fbeafabcb198503cf6caa7dc4"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-18798.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67165-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18798"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260825.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18798"
        }
      ],
      "published": "2026-08-25T13:17:49+00:00",
      "updated": "2026-09-23T16:07:09+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-18839",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.2,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        191
      ],
      "description": "An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who can cause an application to print help under those conditions may cause that application to crash or fail to display help, resulting in a denial of service of the affected application.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18839"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:77932"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2511010"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18839"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18839"
        }
      ],
      "published": "2026-08-05T21:16:57+00:00",
      "updated": "2026-10-08T15:17:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.18-8.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-18924",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-18924"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18924"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-18924.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-18924.json"
        },
        {
          "url": "https://github.com/curl/curl/commit/90325ff0444cbdff368bda5d26d6"
        },
        {
          "url": "https://hackerone.com/reports/3916059"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18924"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8820-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18924"
        }
      ],
      "published": "2026-09-06T18:17:20+00:00",
      "updated": "2026-09-15T07:16:27+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-19445",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        416
      ],
      "description": "A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-19445"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/09/30/17"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:77028"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-19445"
        },
        {
          "url": "https://bugzilla.redhat.com/2544127"
        },
        {
          "url": "https://bugzilla.redhat.com/2544138"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2544127"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2544138"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19553"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2026-77028.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:77028"
        },
        {
          "url": "https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d"
        },
        {
          "url": "https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b"
        },
        {
          "url": "https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7"
        },
        {
          "url": "https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8"
        },
        {
          "url": "https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698"
        },
        {
          "url": "https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c"
        },
        {
          "url": "https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b"
        },
        {
          "url": "https://github.com/python/cpython/issues/156293"
        },
        {
          "url": "https://github.com/python/cpython/pull/158504"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-19445.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-77028.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19445"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-19445"
        }
      ],
      "published": "2026-09-30T17:16:45+00:00",
      "updated": "2026-10-03T01:17:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-19542",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121
      ],
      "description": "Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified.",
      "recommendation": "Upgrade glibc to version 2.34-283.el9_8; Upgrade glibc-common to version 2.34-283.el9_8; Upgrade glibc-minimal-langpack to version 2.34-283.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-19542"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-19542"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19542"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34506"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-19542"
        }
      ],
      "published": "2026-09-14T18:17:46+00:00",
      "updated": "2026-09-18T18:17:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-19553",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        297
      ],
      "description": "ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-19553"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/09/30/16"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:77028"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-19553"
        },
        {
          "url": "https://bugzilla.redhat.com/2544127"
        },
        {
          "url": "https://bugzilla.redhat.com/2544138"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2544127"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2544138"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19445"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19553"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2026-77028.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:77028"
        },
        {
          "url": "https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96"
        },
        {
          "url": "https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf"
        },
        {
          "url": "https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082"
        },
        {
          "url": "https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed"
        },
        {
          "url": "https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced"
        },
        {
          "url": "https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80"
        },
        {
          "url": "https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062"
        },
        {
          "url": "https://github.com/python/cpython/issues/156793"
        },
        {
          "url": "https://github.com/python/cpython/pull/158503"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-19553.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-77028.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19553"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-19553"
        }
      ],
      "published": "2026-09-30T17:16:45+00:00",
      "updated": "2026-10-03T01:17:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-19672",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        22
      ],
      "description": "The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-19672"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/08/25/10"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-19672"
        },
        {
          "url": "https://github.com/python/cpython/pull/156000"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19672"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-19672"
        }
      ],
      "published": "2026-08-19T16:17:06+00:00",
      "updated": "2026-08-28T21:16:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-19931",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "cwes": [
        488
      ],
      "description": "A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-19931"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-19931"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-19931.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-19931.json"
        },
        {
          "url": "https://hackerone.com/reports/3923520"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19931"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-19931"
        }
      ],
      "published": "2026-09-06T18:17:20+00:00",
      "updated": "2026-09-15T07:16:27+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-22185",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125,
        191
      ],
      "description": "OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-22185"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-22185"
        },
        {
          "url": "https://bugs.openldap.org/show_bug.cgi?id=10421"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22185"
        },
        {
          "url": "https://seclists.org/fulldisclosure/2026/Jan/5"
        },
        {
          "url": "https://seclists.org/fulldisclosure/2026/Jan/8"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22185"
        },
        {
          "url": "https://www.openldap.org/"
        },
        {
          "url": "https://www.vulncheck.com/advisories/openldap-lmdb-mdb-load-heap-buffer-underflow-in-readline"
        }
      ],
      "published": "2026-01-07T21:16:01+00:00",
      "updated": "2026-06-17T10:19:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.6.8-4.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-22693",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault. This issue has been patched in version 12.3.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-22693"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/11/1"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/12/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-22693"
        },
        {
          "url": "https://github.com/harfbuzz/harfbuzz/commit/1265ff8d990284f04d8768f35b0e20ae5f60daae"
        },
        {
          "url": "https://github.com/harfbuzz/harfbuzz/security/advisories/GHSA-xvjr-f2r9-c7ww"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22693"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22693"
        }
      ],
      "published": "2026-01-10T06:15:52+00:00",
      "updated": "2026-06-17T10:20:14+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.7.4-10.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/harfbuzz@2.7.4-10.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-2297",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        668
      ],
      "description": "The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.audit handlers for this audit event therefore do not fire.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-2297"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/05/6"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-2297"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/482d6f8bdba9da3725d272e8bb4a2d25fb6a603e"
        },
        {
          "url": "https://github.com/python/cpython/commit/69ddd9bb2cc4bd69b1565647c18659c6a789ccd9"
        },
        {
          "url": "https://github.com/python/cpython/commit/876858c9f65d9ab656c7fa639f268ce7856d89dd"
        },
        {
          "url": "https://github.com/python/cpython/commit/a51b1b512de1d56b3714b65628a2eae2b07e535e"
        },
        {
          "url": "https://github.com/python/cpython/commit/c70adad78caeeea33f92f560ecb93331ca11bf66"
        },
        {
          "url": "https://github.com/python/cpython/commit/e58e9802b9bec5cdbf48fc9bf1da5f4fda482e86"
        },
        {
          "url": "https://github.com/python/cpython/issues/145506"
        },
        {
          "url": "https://github.com/python/cpython/pull/145507"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-2297.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2297"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-2297"
        }
      ],
      "published": "2026-03-04T23:16:10+00:00",
      "updated": "2026-08-13T01:16:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-23865",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-23865"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/03/8"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9689"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:9693"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-23865"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2443891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460038"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460039"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460040"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460041"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460042"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460043"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460044"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22007"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22013"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22016"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22018"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-22021"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-23865"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34268"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34282"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-9693.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:9689"
        },
        {
          "url": "https://github.com/advisories/GHSA-878v-mxg6-vj8f"
        },
        {
          "url": "https://gitlab.com/freetype/freetype/-/commit/fc85a255849229c024c8e65f536fe1875d84841c"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-23865.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-9693.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23865"
        },
        {
          "url": "https://sourceforge.net/projects/freetype/files/freetype2/2.14.2"
        },
        {
          "url": "https://sourceforge.net/projects/freetype/files/freetype2/2.14.2/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8086-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8327-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8328-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8330-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8331-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8332-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8333-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8334-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8339-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8341-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-23865"
        },
        {
          "url": "https://www.facebook.com/security/advisories/cve-2026-23865"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuapr2026.html#AppendixJAVA"
        }
      ],
      "published": "2026-03-02T17:16:32+00:00",
      "updated": "2026-06-17T10:22:13+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.10.4-10.el9_5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-24515",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 2.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-24515"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-24515"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1131"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24515"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8022-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8022-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8023-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24515"
        }
      ],
      "published": "2026-01-23T08:16:01+00:00",
      "updated": "2026-06-17T10:23:10+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-24883",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        476
      ],
      "description": "In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leading to a denial of service (application crash).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-24883"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-24883"
        },
        {
          "url": "https://dev.gnupg.org/T8049"
        },
        {
          "url": "https://github.com/advisories/GHSA-7246-cvp4-g68w"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24883"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24883"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/01/27/8"
        }
      ],
      "published": "2026-01-27T19:16:16+00:00",
      "updated": "2026-06-17T10:23:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.3.3-5.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-25068",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        129
      ],
      "description": "alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based buffer overflow in the topology mixer control decoder. The tplg_decode_control_mixer1() function reads the num_channels field from untrusted .tplg data and uses it as a loop bound without validating it against the fixed-size channel array (SND_TPLG_MAX_CHAN). A crafted topology file with an excessive num_channels value can cause out-of-bounds heap writes, leading to a crash.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-25068"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-25068"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/commit/5f7fe33002d2d98d84f72e381ec2cccc0d5d3d40"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/02/msg00008.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25068"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8044-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8044-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-25068"
        },
        {
          "url": "https://www.vulncheck.com/advisories/alsa-lib-topology-decoder-heap-based-buffer-overflow"
        }
      ],
      "published": "2026-01-29T20:16:10+00:00",
      "updated": "2026-06-17T10:24:04+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.2.15.3-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-25645",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        377
      ],
      "description": "Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulnerability. Only applications that call `extract_zipped_paths()` directly are impacted. Starting in version 2.33.0, the library extracts files to a non-deterministic location. If developers are unable to upgrade, they can set `TMPDIR` in their environment to a directory with restricted write access.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-25645"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-25645"
        },
        {
          "url": "https://github.com/psf/requests"
        },
        {
          "url": "https://github.com/psf/requests/commit/66d21cb07bd6255b1280291c4fafb71803cdb3b7"
        },
        {
          "url": "https://github.com/psf/requests/releases/tag/v2.33.0"
        },
        {
          "url": "https://github.com/psf/requests/security/advisories/GHSA-gc5v-m9x4-r6x2"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25645"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8825-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-25645"
        }
      ],
      "published": "2026-03-25T17:16:52+00:00",
      "updated": "2026-06-17T10:25:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "21.3.1-2.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-27171",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "cbl-mariner"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        1284
      ],
      "description": "zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-27171"
        },
        {
          "url": "https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit"
        },
        {
          "url": "https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/"
        },
        {
          "url": "https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-27171"
        },
        {
          "url": "https://github.com/advisories/GHSA-h858-mf2m-8jf4"
        },
        {
          "url": "https://github.com/madler/zlib/issues/904"
        },
        {
          "url": "https://github.com/madler/zlib/releases/tag/v1.3.2"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27171"
        },
        {
          "url": "https://ostif.org/zlib-audit-complete"
        },
        {
          "url": "https://ostif.org/zlib-audit-complete/"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8706-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-27171"
        }
      ],
      "published": "2026-02-18T04:16:01+00:00",
      "updated": "2026-06-17T10:26:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.2.11-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-27456",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bottlerocket"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        59,
        269,
        367
      ],
      "description": "util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-27456"
        },
        {
          "url": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27456"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-27456"
        },
        {
          "url": "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-jgcxwcxt3sxd.toml"
        },
        {
          "url": "https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4"
        },
        {
          "url": "https://github.com/util-linux/util-linux/releases/tag/v2.41.4"
        },
        {
          "url": "https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27456"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8702-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-27456"
        }
      ],
      "published": "2026-04-03T22:16:25+00:00",
      "updated": "2026-07-24T22:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-28387",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        416
      ],
      "description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based\nserver authentication, when paired with uncommon server DANE TLSA records, may\nresult in a use-after-free and/or double-free on the client side.\n\nImpact summary: A use after free can have a range of potential consequences\nsuch as the corruption of valid data, crashes or execution of arbitrary code.\n\nHowever, the issue only affects clients that make use of TLSA records with both\nthe PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate\nusage.\n\nBy far the most common deployment of DANE is in SMTP MTAs for which RFC7672\nrecommends that clients treat as 'unusable' any TLSA records that have the PKIX\ncertificate usages.  These SMTP (or other similar) clients are not vulnerable\nto this issue.  Conversely, any clients that support only the PKIX usages, and\nignore the DANE-TA(2) usage are also not vulnerable.\n\nThe client would also need to be communicating with a server that publishes a\nTLSA RRset with both types of TLSA records.\n\nNo FIPS modules are affected by this issue, the problem code is outside the\nFIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-28387"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-28387"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/07e727d304746edb49a98ee8f6ab00256e1f012b"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/258a8f63b26995ba357f4326da00e19e29c6acbe"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/444958deaf450aea819171f97ae69eaedede42c3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7a4e08cee62a728d32e60b0de89e6764339df0a7"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ec03fa050b3346997ed9c5fef3d0e16ad7db8177"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28387"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-28387"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:20+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-28388",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension\nis processed a NULL pointer dereference might happen if the required CRL\nNumber extension is missing.\n\nImpact summary: A NULL pointer dereference can trigger a crash which\nleads to a Denial of Service for an application.\n\nWhen CRL processing and delta CRL processing is enabled during X.509\ncertificate verification, the delta CRL processing does not check\nwhether the CRL Number extension is NULL before dereferencing it.\nWhen a malformed delta CRL file is being processed, this parameter\ncan be NULL, causing a NULL pointer dereference.\n\nExploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in\nthe verification context, the certificate being verified to contain a\nfreshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and\nan attacker to provide a malformed CRL to an application that processes it.\n\nThe vulnerability is limited to Denial of Service and cannot be escalated to\nachieve code execution or memory disclosure. For that reason the issue was\nassessed as Low severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-28388"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-28388"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/59c3b3158553ab53275bbbccca5cb305d591cf2e"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/5a0b4930779cd2408880979db765db919da55139"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/602542f2c0c2d5edb47128f93eac10b62aeeefb3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a9d187dd1000130100fa7ab915f8513532cb3bb8"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d3a901e8d9f021f3e67d6cfbc12e768129862726"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28388"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-28388"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:20+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-28389",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is\nprocessed, the optional parameters field of KeyEncryptionAlgorithmIdentifier\nis examined without checking for its presence. This results in a NULL\npointer dereference if the field is missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-28389"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-28389"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "url": "https://github.com/advisories/GHSA-7x88-9hgc-69gf"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/16cea4188e0ea567deb4f93f85902247e67384f5"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/785cbf7ea3b5a6f5adf0c1ccb92b79d89c35c616"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7b5274e812400cacb6f3be4c2df5340923fa807f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/c6725634e089eb2b634b10ede33944be7248172a"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f80f83bc5fd036bc47d773e8b15a001e2b4ce686"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28389"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-28389"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:21+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-31789",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.8,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.8,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Issue summary: Converting an excessively large OCTET STRING value to\na hexadecimal string leads to a heap buffer overflow on 32 bit platforms.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nan attacker controlled code execution or other undefined behavior.\n\nIf an attacker can supply a crafted X.509 certificate with an excessively\nlarge OCTET STRING value in extensions such as the Subject Key Identifier\n(SKID) or Authority Key Identifier (AKID) which are being converted to hex,\nthe size of the buffer needed for the result is calculated as multiplication\nof the input length by 3. On 32 bit platforms, this multiplication may overflow\nresulting in the allocation of a smaller buffer and a heap buffer overflow.\n\nApplications and services that print or log contents of untrusted X.509\ncertificates are vulnerable to this issue. As the certificates would have\nto have sizes of over 1 Gigabyte, printing or logging such certificates\nis a fairly unlikely operation and only 32 bit platforms are affected,\nthis issue was assigned Low severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-31789"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-31789"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html"
        },
        {
          "url": "https://github.com/advisories/GHSA-j79m-9jxq-788r"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/364f095b80601db632b0def6a33316967f863bde"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7a9087efd769f362ad9c0e30c7baaa6bbfa65ecf"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/945b935ac66cc7f1a41f1b849c7c25adb5351f49"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a24216018e1ede8ff01a4ff5afff7dfbd443e2f9"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a91e537d16d74050dbde50bb0dfb1fe9930f0521"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31789"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260407.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8155-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31789"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/07/11"
        }
      ],
      "published": "2026-04-07T22:16:21+00:00",
      "updated": "2026-07-24T23:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-31911",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        617
      ],
      "description": "libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode.  In particular uncommon use cases a crafted filter program can terminate the OS process.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-31911"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-31911"
        },
        {
          "url": "https://github.com/the-tcpdump-group/libpcap/commit/a715bcdde830299cba4171514385cb17ec19b6e9"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31911"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31911"
        }
      ],
      "published": "2026-09-05T19:16:55+00:00",
      "updated": "2026-09-08T19:20:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14",
          "versions": [
            {
              "version": "14:1.10.0-4.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-31912",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "cwes": [
        125,
        823,
        1285
      ],
      "description": "libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer.  In particular uncommon use cases a crafted filter program can cause the interpreter to try reading the OS process memory in the 32GiB around the buffer on 64-bit architectures and in the entire address space on 32-bit architectures.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-31912"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-31912"
        },
        {
          "url": "https://github.com/the-tcpdump-group/libpcap/commit/d3f358d3cffbe1ecb94d5284b3e81f052a0adcb9"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31912"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31912"
        }
      ],
      "published": "2026-09-05T19:16:55+00:00",
      "updated": "2026-09-08T19:20:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14",
          "versions": [
            {
              "version": "14:1.10.0-4.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-32284",
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "The msgpack decoder fails to properly validate the input buffer length when processing truncated fixext data (format codes 0xd4-0xd8). This can lead to an out-of-bounds read and a runtime panic, allowing a denial of service attack.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32284"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32284"
        },
        {
          "url": "https://github.com/golang/vulndb/issues/4513"
        },
        {
          "url": "https://github.com/shamaton/msgpack"
        },
        {
          "url": "https://github.com/shamaton/msgpack/issues/59"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32284"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4513"
        },
        {
          "url": "https://securityinfinity.com/research/shamaton-msgpack-oob-panic-fixext-dos-2026"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32284"
        }
      ],
      "published": "2026-03-26T20:16:12+00:00",
      "updated": "2026-10-07T18:17:20+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "21.3.1-2.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3276",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        407
      ],
      "description": "unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3276"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/06/03/15"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3276"
        },
        {
          "url": "https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0"
        },
        {
          "url": "https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598"
        },
        {
          "url": "https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f"
        },
        {
          "url": "https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32"
        },
        {
          "url": "https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066"
        },
        {
          "url": "https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1f"
        },
        {
          "url": "https://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacc"
        },
        {
          "url": "https://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2c"
        },
        {
          "url": "https://github.com/python/cpython/issues/149079"
        },
        {
          "url": "https://github.com/python/cpython/pull/149080"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3276"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3276"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/06/03/15"
        }
      ],
      "published": "2026-06-03T16:16:29+00:00",
      "updated": "2026-08-13T01:16:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-32776",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32776"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32776"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1158"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1159"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32776"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8790-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32776"
        }
      ],
      "published": "2026-03-16T14:19:44+00:00",
      "updated": "2026-07-14T13:18:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-32777",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        835
      ],
      "description": "libexpat before 2.7.5 allows an infinite loop while parsing DTD content.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32777"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32777"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/issues/1161"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1159"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1162"
        },
        {
          "url": "https://issues.oss-fuzz.com/issues/486993411"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32777"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8790-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32777"
        }
      ],
      "published": "2026-03-16T14:19:44+00:00",
      "updated": "2026-07-14T13:18:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-32778",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-32778"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-32778"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1159"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1163"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32778"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8790-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32778"
        }
      ],
      "published": "2026-03-16T14:19:44+00:00",
      "updated": "2026-07-14T13:18:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-33056",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        61
      ],
      "description": "tar-rs is a tar archive reading/writing library for Rust. In versions 0.4.44 and below, when unpacking a tar archive, the tar crate's unpack_dir function uses fs::metadata() to check whether a path that already exists is a directory. Because fs::metadata() follows symbolic links, a crafted tarball containing a symlink entry followed by a directory entry with the same name causes the crate to treat the symlink target as a valid existing directory \u2014 and subsequently apply chmod to it. This allows an attacker to modify the permissions of arbitrary directories outside the extraction root. This issue has been fixed in version 0.4.45.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-33056"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-33056"
        },
        {
          "url": "https://github.com/alexcrichton/tar-rs"
        },
        {
          "url": "https://github.com/alexcrichton/tar-rs/commit/17b1fd84e632071cb8eef9d3709bf347bd266446"
        },
        {
          "url": "https://github.com/alexcrichton/tar-rs/security/advisories/GHSA-j4xf-2g29-59ph"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33056"
        },
        {
          "url": "https://rustsec.org/advisories/RUSTSEC-2026-0067.html"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8138-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8139-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8168-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33056"
        }
      ],
      "published": "2026-03-20T08:16:11+00:00",
      "updated": "2026-06-17T10:36:52+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.34-13.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.34-13.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/tar@1.34-13.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-34743",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        122
      ],
      "description": "XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-34743"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/31/13"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:64787"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-34743"
        },
        {
          "url": "https://bugzilla.redhat.com/2454589"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2454589"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34743"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-64787.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:64787"
        },
        {
          "url": "https://github.com/tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87"
        },
        {
          "url": "https://github.com/tukaani-project/xz/releases/tag/v5.8.3"
        },
        {
          "url": "https://github.com/tukaani-project/xz/security/advisories/GHSA-x872-m794-cxhv"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-34743.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-64787-0.html"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/07/msg00034.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34743"
        },
        {
          "url": "https://tukaani.org/xz/index-append-overflow.html"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8362-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34743"
        }
      ],
      "published": "2026-04-02T19:21:33+00:00",
      "updated": "2026-07-24T21:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "5.2.5-8.el9_0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-34757",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.0.9 to before 1.6.57, passing a pointer obtained from png_get_PLTE, png_get_tRNS, or png_get_hIST back into the corresponding setter on the same png_struct/png_info pair causes the setter to read from freed memory and copy its contents into the replacement buffer. The setter frees the internal buffer before copying from the caller-supplied pointer, which now dangles. The freed region may contain stale data (producing silently corrupted chunk metadata) or data from subsequent heap allocations (leaking unrelated heap contents into the chunk struct). This vulnerability is fixed in 1.6.57.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-34757"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-34757"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/398cbe3df03f4e11bb031e07f416dfdde3684e8a"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc"
        },
        {
          "url": "https://github.com/pnggroup/libpng/issues/836"
        },
        {
          "url": "https://github.com/pnggroup/libpng/issues/837"
        },
        {
          "url": "https://github.com/pnggroup/libpng/security/advisories/GHSA-6fr7-g8h7-v645"
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/05/msg00017.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34757"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8251-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8639-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34757"
        }
      ],
      "published": "2026-04-09T15:16:11+00:00",
      "updated": "2026-06-17T10:39:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.6.37-15.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3479",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "cwes": [
        22
      ],
      "description": "DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.\n\npkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3479"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3479"
        },
        {
          "url": "https://github.com/python/cpython/commit/5af6ce3e7b643a30a02d22245c1e3f4a8bc0a1fe"
        },
        {
          "url": "https://github.com/python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7"
        },
        {
          "url": "https://github.com/python/cpython/commit/cf59bf76470f3d75ad47d80ffb8ce76b64b5e943"
        },
        {
          "url": "https://github.com/python/cpython/commit/d786d59a8f7196bb630100a869f28ad13436b59c"
        },
        {
          "url": "https://github.com/python/cpython/issues/146121"
        },
        {
          "url": "https://github.com/python/cpython/pull/146122"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3479"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3479"
        }
      ],
      "published": "2026-03-18T19:16:06+00:00",
      "updated": "2026-06-17T10:43:39+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-35189",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-35189"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-35189"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35189"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-35189"
        }
      ],
      "published": "2026-09-29T16:17:07+00:00",
      "updated": "2026-10-08T01:01:54+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-35191",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        440
      ],
      "description": "Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL's QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-35191"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-35191"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35191"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-35191"
        }
      ],
      "published": "2026-09-29T16:17:07+00:00",
      "updated": "2026-10-08T01:02:06+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-3644",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        20,
        116
      ],
      "description": "The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3644"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/3974092b037f9a3b000fb15b48ea61ce3b25d330"
        },
        {
          "url": "https://github.com/python/cpython/commit/556aa098e738b127c714866f819b4abe2f7593d8"
        },
        {
          "url": "https://github.com/python/cpython/commit/57e88c1cf95e1481b94ae57abe1010469d47a6b4"
        },
        {
          "url": "https://github.com/python/cpython/commit/62ceb396fcbe69da1ded3702de586f4072b590dd"
        },
        {
          "url": "https://github.com/python/cpython/commit/d16ecc6c3626f0e2cc8f08c309c83934e8a979dd"
        },
        {
          "url": "https://github.com/python/cpython/commit/dae4b1a21f8df4570e30986affd61bbe4ade4cef"
        },
        {
          "url": "https://github.com/python/cpython/issues/145599"
        },
        {
          "url": "https://github.com/python/cpython/pull/145600"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-3644.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/H6CADMBCDRFGWCMOXWUIHFJNV43GABJ7/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3644"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8744-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3644"
        }
      ],
      "published": "2026-03-16T18:16:09+00:00",
      "updated": "2026-08-13T01:16:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-3784",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        305
      ],
      "description": "curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a\nserver, even if the new request uses different credentials for the HTTP proxy.\nThe proper behavior is to create or use a separate connection.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-3784"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/11/3"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3784"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-3784.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-3784.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-5q3w-6p3j-mw6p"
        },
        {
          "url": "https://hackerone.com/reports/3584903"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-3784.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-55450.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3784"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8084-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8099-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3784"
        }
      ],
      "published": "2026-03-11T11:16:00+00:00",
      "updated": "2026-09-15T07:16:27+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-40467",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "Use After Free vulnerability has been found in \"io.c\" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects\u00a0gawk in versions 5.4.0 and below.",
      "recommendation": "Upgrade gawk to version 5.1.0-6.el9_8.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-40467"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73512"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-40467"
        },
        {
          "url": "https://bugzilla.redhat.com/2499655"
        },
        {
          "url": "https://bugzilla.redhat.com/2499657"
        },
        {
          "url": "https://bugzilla.redhat.com/2499658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499658"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-40467"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=a2d18c74109e41bec29a23098eba2e00057286d8"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40553"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-73512.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:73512"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-40467.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-73512.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40467"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8588-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-40467"
        }
      ],
      "published": "2026-07-13T13:16:36+00:00",
      "updated": "2026-07-14T01:13:59+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "5.1.0-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-40468",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "Integer overflow vulnerability has been found in \"builtin.c\" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects\u00a0gawk in versions 5.4.0 and below.",
      "recommendation": "Upgrade gawk to version 5.1.0-6.el9_8.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-40468"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73512"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-40468"
        },
        {
          "url": "https://bugzilla.redhat.com/2499655"
        },
        {
          "url": "https://bugzilla.redhat.com/2499657"
        },
        {
          "url": "https://bugzilla.redhat.com/2499658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499658"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-40467"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=062f2f2581b991362c046f7f2e238ffa34e6f8c7"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40553"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-73512.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:73512"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-40468.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-73512.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40468"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8588-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-40468"
        }
      ],
      "published": "2026-07-13T13:16:36+00:00",
      "updated": "2026-07-14T01:12:11+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "5.1.0-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-40553",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121
      ],
      "description": "Buffer overflow vulnerability has been found in \"extension/readdir.c\" program file of gawk (ftype()\u00a0routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects\u00a0gawk in versions 5.4.0 and below.",
      "recommendation": "Upgrade gawk to version 5.1.0-6.el9_8.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-40553"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:73512"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-40553"
        },
        {
          "url": "https://bugzilla.redhat.com/2499655"
        },
        {
          "url": "https://bugzilla.redhat.com/2499657"
        },
        {
          "url": "https://bugzilla.redhat.com/2499658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499658"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-40467"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=cca0366144336b49aaa7d5d949966ce8e2c70843"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40467"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40468"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40553"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-73512.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:73512"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-40553.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-73512.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40553"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8588-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-40553"
        }
      ],
      "published": "2026-07-13T13:16:37+00:00",
      "updated": "2026-07-14T01:10:20+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "5.1.0-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/gawk@5.1.0-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-40930",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        436
      ],
      "description": "LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. In version 1.8.0, three inter-frame chunk discard paths in the push-mode APNG parser clear the chunk-header flag without consuming the chunk body and CRC, allowing attacker-controlled bytes inside an ignored ancillary chunk to be reinterpreted as a fresh chunk header on the next call to `png_process_data`. Commit faf06924688b62d7c1654b5ceddedbde66ffadb4 fixes the issue.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-40930"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/05/15/21"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-40930"
        },
        {
          "url": "https://github.com/pnggroup/libpng/commit/faf06924688b62d7c1654b5ceddedbde66ffadb4"
        },
        {
          "url": "https://github.com/pnggroup/libpng/security/advisories/GHSA-c4v6-gxrq-6g2x"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40930"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8639-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-40930"
        }
      ],
      "published": "2026-06-04T16:16:36+00:00",
      "updated": "2026-07-22T20:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.6.37-15.el9_8.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libpng@1.6.37-15.el9_8.2?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-4105",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        284
      ],
      "description": "A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4105"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:7299"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4105"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2447262"
        },
        {
          "url": "https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4105"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4105"
        }
      ],
      "published": "2026-03-13T19:55:13+00:00",
      "updated": "2026-09-01T13:19:38+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "252-67.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "252-67.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "252-67.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "252-67.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/systemd-libs@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/systemd-pam@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.4?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/systemd@252-67.el9_8.4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-41080",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        331
      ],
      "description": "libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-41080"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/26/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-41080"
        },
        {
          "url": "https://blog.hartwork.org/posts/expat-2-8-0-released/"
        },
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "url": "https://github.com/libexpat/libexpat/issues/47"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1183"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41080"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8520-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8790-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41080"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/26/1"
        }
      ],
      "published": "2026-04-16T17:16:54+00:00",
      "updated": "2026-07-14T13:18:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-41990",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.3,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-41990"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-41990"
        },
        {
          "url": "https://dev.gnupg.org/T8208"
        },
        {
          "url": "https://github.com/advisories/GHSA-78pv-qq8x-94px"
        },
        {
          "url": "https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41990"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8319-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41990"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/04/21/1"
        }
      ],
      "published": "2026-04-23T05:16:05+00:00",
      "updated": "2026-06-17T10:47:18+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcrypt@1.10.0-13.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.10.0-13.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libgcrypt@1.10.0-13.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libgcrypt@1.10.0-13.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libgcrypt@1.10.0-13.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libgcrypt@1.10.0-13.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libgcrypt@1.10.0-13.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libgcrypt@1.10.0-13.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libgcrypt@1.10.0-13.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libgcrypt@1.10.0-13.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libgcrypt@1.10.0-13.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libgcrypt@1.10.0-13.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libgcrypt@1.10.0-13.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libgcrypt@1.10.0-13.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libgcrypt@1.10.0-13.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libgcrypt@1.10.0-13.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libgcrypt@1.10.0-13.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-4224",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        674
      ],
      "description": "When an Expat parser with a registered ElementDeclHandler parses an inline\ndocument type definition containing a deeply nested content model a C stack\noverflow occurs.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4224"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/03/16/4"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4224"
        },
        {
          "url": "https://bugzilla.redhat.com/2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2395108"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2408891"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418084"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431366"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431374"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13837"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15282"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-59375"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0672"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19177.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19177"
        },
        {
          "url": "https://github.com/python/cpython/commit/196edfb06a7458377d4d0f4b3cd41724c1f3bd4a"
        },
        {
          "url": "https://github.com/python/cpython/commit/24ce88b285f56ee11626cf5e472af3cd8cc7c621"
        },
        {
          "url": "https://github.com/python/cpython/commit/642865ddf4b232da1f3b1f7abcfa3254c4bfe785"
        },
        {
          "url": "https://github.com/python/cpython/commit/af856a7177326ac25d9f66cc6dd28b554d914fee"
        },
        {
          "url": "https://github.com/python/cpython/commit/e0a8a6da90597a924b300debe045cdb4628ee1f3"
        },
        {
          "url": "https://github.com/python/cpython/commit/eb0e8be3a7e11b87d198a2c3af1ed0eccf532768"
        },
        {
          "url": "https://github.com/python/cpython/issues/145986"
        },
        {
          "url": "https://github.com/python/cpython/pull/145987"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-4224.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19177.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/5M7CGUW3XBRY7II4DK43KF7NQQ3TPZ6R/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4224"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8744-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4224"
        }
      ],
      "published": "2026-03-16T18:16:10+00:00",
      "updated": "2026-08-13T01:16:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42250",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        787
      ],
      "description": "bzip2 contains an off\u2011by\u2011one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out\u2011of\u2011bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).\n\nThis issue was fixed in bzip2 patch\u00a035d122a3df8b0cc4082a4d89fdc6ee99f375fe67",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42250"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42250"
        },
        {
          "url": "https://cert.pl/en/posts/2026/05/CVE-2026-42250/"
        },
        {
          "url": "https://inbox.sourceware.org/bzip2-devel/20260528145407.293768-1-mark@klomp.org/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42250"
        },
        {
          "url": "https://sourceware.org/bzip2/"
        },
        {
          "url": "https://sourceware.org/cgit/bzip2/commit/?id=35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8685-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42250"
        }
      ],
      "published": "2026-05-28T14:16:19+00:00",
      "updated": "2026-06-17T10:47:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.0.8-11.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42308",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42308"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42308"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-42308"
        },
        {
          "url": "https://github.com/advisories/GHSA-wjx4-4jcj-g98j"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-165.yaml"
        },
        {
          "url": "https://github.com/python-pillow/Pillow"
        },
        {
          "url": "https://github.com/python-pillow/Pillow/pull/9518/changes%20%28suspected%20fix%29"
        },
        {
          "url": "https://github.com/python-pillow/Pillow/releases/tag/12.2.0"
        },
        {
          "url": "https://github.com/python-pillow/Pillow/security/advisories/GHSA-wjx4-4jcj-g98j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42308"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8399-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42308"
        }
      ],
      "published": "2026-05-09T06:16:09+00:00",
      "updated": "2026-07-24T21:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-42765",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: When a partial-chain certificate verification is enabled\ntogether with OCSP response checking for the whole chain, a NULL dereference\nwill happen if the verified chain does not have a self-signed trusted anchor,\ncrashing the process.\n\nImpact summary: A NULL pointer dereference can trigger a crash which leads to a\nDenial of Service for an application.\n\nWhen performing OCSP response checking for certificates in the verification\nchain, the code always tries to access the next certificate as the issuer.\nThere is a check for a self-signed certificate. However with the partial\nchain verification enabled when the chain does not have a self-signed trusted\nanchor, the issuer will be NULL for the last certificate in the chain. A NULL\npointer dereference then happens.\n\nThis issue affects only applications which enable both OCSP verification\nof the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial\nchain verification (X509_V_FLAG_PARTIAL_CHAIN) in the certificate\nverification. Both flags are disabled by default. For that reason, we have\nassigned Low severity to the issue.\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42765"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42765"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/14340b7fa1d444615486bc137014b064e64ec334"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/eb345da18ce2216b2f3ade9c2bc23e068487fa97"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42765"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42765"
        }
      ],
      "published": "2026-06-09T17:17:07+00:00",
      "updated": "2026-07-23T08:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-42772",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        407
      ],
      "description": "Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-42772"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-42772"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42772"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8861-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42772"
        }
      ],
      "published": "2026-09-29T16:17:07+00:00",
      "updated": "2026-10-08T01:18:57+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-4360",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        281
      ],
      "description": "In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4360"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4360"
        },
        {
          "url": "https://github.com/python/cpython/commit/0367912be336348b30572f8029cec4a282782d92"
        },
        {
          "url": "https://github.com/python/cpython/commit/5e0ef3f1afe892e4f64eb83368db57ac4c40cba0"
        },
        {
          "url": "https://github.com/python/cpython/commit/7b57e8d51446297b8c7c482d224bc5f1938e4301"
        },
        {
          "url": "https://github.com/python/cpython/commit/7ccdbaba2c54250a70d7f25632152df7655a5e0a"
        },
        {
          "url": "https://github.com/python/cpython/commit/cf23b9153181062150d061468b6d24af33fe214f"
        },
        {
          "url": "https://github.com/python/cpython/commit/d2b2f5eacab4dd48446b63340613b05dcbbf0b44"
        },
        {
          "url": "https://github.com/python/cpython/commit/eee3ddf0ca10283cc7fea724aae9cd8665f8d15e"
        },
        {
          "url": "https://github.com/python/cpython/issues/151987"
        },
        {
          "url": "https://github.com/python/cpython/pull/151988"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/TWZW2PC2AZOV6FENIHFSRC63OM7MBGSB/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4360"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8744-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4360"
        }
      ],
      "published": "2026-06-30T15:16:57+00:00",
      "updated": "2026-08-13T01:16:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-4426",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1335
      ],
      "description": "A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4426"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8944"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4426"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449010"
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/2897"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4426"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8292-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4426"
        }
      ],
      "published": "2026-03-19T15:16:28+00:00",
      "updated": "2026-09-01T13:19:39+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-11.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-44605",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-44605"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33507"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44605"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2482481"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44605"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44605"
        }
      ],
      "published": "2026-08-05T18:17:11+00:00",
      "updated": "2026-08-31T13:18:18+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-45409",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        1333
      ],
      "description": "Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `\"\\u0660\" * N` or `\"\\u30fb\" * N + \"\\u6f22\"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fix. A specially crafted argument to the `idna.encode()` function could consume significant resources. This may lead to a denial-of-service. Starting in version 3.14, the function rejects long inputs as soon as practicable prior to any further processing to minimize resource consumption. In version 3.15, this approach was extended to lesser used alternate functions (i.e. per-label conversions and codec support). A workaround is available. Domain names cannot exceed 253 characters in length. If this length limit is enforced prior to passing the domain to the `idna.encode()` function, it should no longer consume significant resources. This is triggered by arbitrarily large inputs that would not occur in normal usage, but may be passed to the library assuming there is no preliminary input validation by the higher-level application.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-45409"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54484"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-45409"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-45409"
        },
        {
          "url": "https://bugzilla.redhat.com/2485616"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2485616"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45409"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-54484.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:54484"
        },
        {
          "url": "https://github.com/kjd/idna"
        },
        {
          "url": "https://github.com/kjd/idna/security/advisories/GHSA-65pc-fj4g-8rjx"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/idna/PYSEC-2026-215.yaml"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-45409.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-54484.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45409"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8549-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45409"
        }
      ],
      "published": "2026-06-05T23:16:43+00:00",
      "updated": "2026-07-23T07:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "21.3.1-2.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-4873",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        319,
        295
      ],
      "description": "A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool. If an initial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-4873"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/7"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-4873"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-4873.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-4873.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-5fgw-rv54-prjx"
        },
        {
          "url": "https://hackerone.com/reports/3621851"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4873"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-4873"
        }
      ],
      "published": "2026-05-13T13:01:55+00:00",
      "updated": "2026-09-15T07:16:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-49919",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H"
        }
      ],
      "cwes": [
        190
      ],
      "description": "In tt_face_colr_blend_layer of ttcolr.c, there is a possible remote code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-49919"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-49919"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49919"
        },
        {
          "url": "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-49919"
        }
      ],
      "published": "2026-09-08T19:17:59+00:00",
      "updated": "2026-09-24T15:47:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.10.4-10.el9_5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-50812",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-50812"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-50812"
        },
        {
          "url": "https://gist.github.com/junius-sec/bb556f333957c5226dede314db0e9e91"
        },
        {
          "url": "https://github.com/sqlite/sqlite/commit/b869ed6b067d623cb1383549f2a18aa35508385d"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50812"
        },
        {
          "url": "https://sqlite.org/src/info/e807d4e3798efd53"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8565-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-50812"
        }
      ],
      "published": "2026-07-08T18:16:32+00:00",
      "updated": "2026-07-09T19:48:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.34.1-11.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-53613",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "description": "When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-53613"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-53613"
        },
        {
          "url": "https://github.com/util-linux/util-linux/security/advisories/GHSA-8gj5-72r3-428g"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53613"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8702-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53613"
        }
      ],
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.37.4-25.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. This is a base-image OS utility vulnerability requiring local shell access and an admin-triggered mount race; not reachable through any CP product code path."
      }
    },
    {
      "id": "CVE-2026-53655",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N"
        }
      ],
      "cwes": [
        436
      ],
      "description": "node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX overrides) to the next header entry of any type, including intermediary metadata headers such as a GNU long-name (L) or long-link (K) entry. Per POSIX pax, a PAX extended header (x) describes the next file entry, not the intermediary extension headers that may sit between the x header and the file it annotates. Because node-tar lets the PAX size override the byte length of an intervening L/K/x header, an attacker can desynchronize node-tar's stream cursor relative to every other mainstream tar implementation (GNU tar, libarchive/bsdtar, Python tarfile, and the now-fixed tar-rs / astral-tokio-tar). The result is a tar parser interpretation differential (CWE-436): a single crafted archive yields a different set of members under node-tar than under the reference tar tools. An attacker can use this to hide a member from one parser while it is visible to another, which defeats security tooling whose scanner and extractor disagree on archive contents (e.g. a malware/secret scanner that lists entries with one library while a downstream step extracts with another) This vulnerability is fixed in 7.5.16.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-53655"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-53655"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-53655"
        },
        {
          "url": "https://github.com/advisories/GHSA-vmf3-w455-68vh"
        },
        {
          "url": "https://github.com/isaacs/node-tar"
        },
        {
          "url": "https://github.com/isaacs/node-tar/security/advisories/GHSA-vmf3-w455-68vh"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53655"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-53655"
        }
      ],
      "published": "2026-06-22T16:16:38+00:00",
      "updated": "2026-06-26T20:03:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.34-13.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.34-13.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/tar@1.34-13.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-54872",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        208
      ],
      "description": "Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54872"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54872"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54872"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54872"
        }
      ],
      "published": "2026-09-29T16:17:08+00:00",
      "updated": "2026-10-08T01:19:04+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-54873",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54873"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54873"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54873"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8861-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54873"
        }
      ],
      "published": "2026-09-29T16:17:08+00:00",
      "updated": "2026-10-08T01:19:18+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-54874",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        405
      ],
      "description": "Issue summary: Receiving a DTLS record for a future epoch while a handshake\nis in progress causes OpenSSL to buffer far more memory than the record\nitself requires.\n\nImpact summary: A peer can use a small amount of network traffic to make an\nOpenSSL DTLS endpoint retain a disproportionately large amount of memory,\nwhich may lead to a Denial of Service.\n\nCWE: CWE-405: Asymmetric Resource Consumption (Amplification)\n\nDescription: While a DTLS handshake is in progress, a peer may legitimately\nhave already moved on to the next epoch (for example, having sent its\nChangeCipherSpec and Finished messages) before the local endpoint has\nprocessed the same transition, typically because of reordering on the\nunderlying UDP transport. OpenSSL buffers such early records so that they\ncan be processed once the local endpoint catches up.\n\nBuffering a record currently retains the entire read buffer it arrived in,\nwhich is sized to hold the largest possible DTLS record (around 16\nkilobytes), rather than just the bytes that make up the record itself. Up\nto 100 such records may be buffered per connection. As a result, a peer\nthat sends a stream of small forged records claiming to belong to the next\nepoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of\nmemory, despite sending only a small fraction of that amount of data over\nthe network.\n\nAn attacker therefore gains a memory amplification factor of around 1200,\nand can multiply the effect across as many associations as it is able to\nopen, making this a remote memory exhaustion Denial of Service risk for\nDTLS servers. Since the memory retained per connection remains bounded,\nand any limit an application already places on the number of concurrent\nassociations also bounds the total exposure, this issue has been assessed\nas Low severity.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.\n\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this\nissue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.2.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.4.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.8.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.7.\nOpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.\n\nPremium support customers only:\nOpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi\nOpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr\n\nThis issue was reported on 18 May 2026 by Amazon Web Services.\nThe fix has been developed by Matt Caswell.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Amazon Web Services\nFixed by: Matt Caswell",
      "recommendation": "Upgrade openssl to version 1:3.5.8-1.el9_8; Upgrade openssl-libs to version 1:3.5.8-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54874"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67165"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54874"
        },
        {
          "url": "https://bugzilla.redhat.com/2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/2517570"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517570"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14456"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14457"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18798"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54874"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63072"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63073"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63074"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67165.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67165"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-54874.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67165-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54874"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260825.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8865-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54874"
        }
      ],
      "published": "2026-08-25T13:19:24+00:00",
      "updated": "2026-09-11T21:16:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-54875",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        208
      ],
      "description": "Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-54875"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-54875"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54875"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54875"
        }
      ],
      "published": "2026-09-29T16:17:08+00:00",
      "updated": "2026-10-08T01:19:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-5545",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        305,
        613
      ],
      "description": "libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1...",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5545"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5545"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5545.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5545.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-6g7g-56fm-f8mp"
        },
        {
          "url": "https://hackerone.com/reports/3642555"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5545"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5545"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-09-15T07:16:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56109",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        415
      ],
      "description": "The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows attackers to corrupt memory by supplying maliciously crafted ALSA configuration text. When parsing nested compound or array configuration blocks, parse_def() fails to check return values before continuing, causing snd_config_delete() to be called twice on the same already-freed node, resulting in a NULL-pointer write or invalid memory read.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56109"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56109"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/commit/536dd6f8affdf5197c12a63a71c92a70b2833cc0"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/releases/tag/v1.2.16.1"
        },
        {
          "url": "https://lore.kernel.org/alsa-devel/CAGt8pqBU0p2voB+qHxWGcNJrKHAcBhAyHUUBPLBN-Yj_SiV6MQ@mail.gmail.com/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56109"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8538-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56109"
        },
        {
          "url": "https://www.vulncheck.com/advisories/alsa-library-double-free-via-parse-def-in-conf-c"
        }
      ],
      "published": "2026-06-22T18:16:48+00:00",
      "updated": "2026-07-14T22:17:18+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.2.15.3-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56131",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56131"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56131"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1267"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56131"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8813-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56131"
        }
      ],
      "published": "2026-06-19T06:17:10+00:00",
      "updated": "2026-06-23T20:15:48+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56391",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "GNU coreutils uniq is vulnerable to an out\u2011of\u2011bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56391"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67886"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56391"
        },
        {
          "url": "https://bugzilla.redhat.com/2506691"
        },
        {
          "url": "https://bugzilla.redhat.com/2506694"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506694"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-56391"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56391"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56392"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-67886.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67886"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"
        },
        {
          "url": "https://github.com/advisories/GHSA-7xvj-m9x7-qgxq"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-56391.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67886.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56391"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8697-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56391"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/07/25/2"
        }
      ],
      "published": "2026-07-24T09:16:25+00:00",
      "updated": "2026-08-26T13:52:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "8.32-41.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56392",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out\u2011of\u2011bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d",
      "recommendation": "Upgrade coreutils-single to version 8.32-41.el9_8.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56392"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66403"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56392"
        },
        {
          "url": "https://bugzilla.redhat.com/2506694"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506694"
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-56391"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56392"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-66403.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:66403"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/"
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"
        },
        {
          "url": "https://github.com/advisories/GHSA-g24f-m2hx-pfgx"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-56392.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67886.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56392"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56392"
        }
      ],
      "published": "2026-07-24T09:16:25+00:00",
      "updated": "2026-10-02T13:57:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "8.32-41.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/coreutils-single@8.32-41.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-56403",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat before 2.8.2 has an integer overflow in storeAtts.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56403"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56403"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1232"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56403"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8790-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56403"
        }
      ],
      "published": "2026-06-21T16:16:26+00:00",
      "updated": "2026-06-23T20:15:16+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56404",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat before 2.8.2 has an integer overflow in addBinding.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56404"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56404"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1249"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56404"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8790-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8872-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56404"
        }
      ],
      "published": "2026-06-21T16:16:27+00:00",
      "updated": "2026-06-23T20:15:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56405",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat before 2.8.2 has an integer overflow in getAttributeId.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56405"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56405"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1251"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56405"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8790-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8872-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56405"
        }
      ],
      "published": "2026-06-21T16:16:27+00:00",
      "updated": "2026-06-23T20:14:51+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56406",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56406"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56406"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1255"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56406"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8813-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56406"
        }
      ],
      "published": "2026-06-21T16:16:27+00:00",
      "updated": "2026-06-23T16:29:06+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-56407",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56407"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56407"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1262"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56407"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8813-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56407"
        }
      ],
      "published": "2026-06-21T16:16:27+00:00",
      "updated": "2026-06-23T16:28:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56412",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56412"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56412"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1278"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56412"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8790-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56412"
        }
      ],
      "published": "2026-06-21T17:16:44+00:00",
      "updated": "2026-06-23T15:31:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-57062",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        1284
      ],
      "description": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-57062"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-57062"
        },
        {
          "url": "https://blog.calif.io/p/how-to-format-a-ciphertext"
        },
        {
          "url": "https://github.com/advisories/GHSA-m6x2-4hhh-669j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57062"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8720-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-57062"
        },
        {
          "url": "https://www.gnupg.org/download"
        },
        {
          "url": "https://www.gnupg.org/download/"
        }
      ],
      "published": "2026-06-23T18:18:10+00:00",
      "updated": "2026-06-25T20:16:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.3.3-5.el9_7",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5713",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121,
        125
      ],
      "description": "The \"profiling.sampling\" module (Python 3.15+) and \"asyncio introspection capabilities\" (3.14+, \"python -m asyncio ps\" and \"python -m asyncio pstree\") features could be used to read and write addresses in a privileged process if that process connected to a malicious or \"infected\" Python process via the remote debugging feature. This vulnerability requires persistently and repeatedly connecting to the process to be exploited, even after the connecting process crashes with high likelihood due to ASLR.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5713"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/15/6"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:19176"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5713"
        },
        {
          "url": "https://bugzilla.redhat.com/2431367"
        },
        {
          "url": "https://bugzilla.redhat.com/2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/2458239"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2444691"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448168"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2448181"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449649"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457409"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458239"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0865"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1502"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2297"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3644"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4224"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4519"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-5713"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6100"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-19176.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:19176"
        },
        {
          "url": "https://github.com/python/cpython/commit/289fd2c97a7e5aecb8b69f94f5e838ccfeee7e67"
        },
        {
          "url": "https://github.com/python/cpython/commit/316f6265b7f9ca4ffed5346b747475ef1943f35d"
        },
        {
          "url": "https://github.com/python/cpython/issues/148178"
        },
        {
          "url": "https://github.com/python/cpython/pull/148187"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-5713.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-19176.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/OG4RHARYSNIE22GGOMVMCRH76L5HKPLM/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5713"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5713"
        }
      ],
      "published": "2026-04-14T16:16:48+00:00",
      "updated": "2026-07-31T14:16:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5745",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare \"d\" or \"default\" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An attacker can exploit this by providing a maliciously crafted archive, causing an application utilizing the libarchive API (such as bsdtar) to crash, resulting in a Denial of Service (DoS).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5745"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:8944"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5745"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455921"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5745"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8581-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5745"
        }
      ],
      "published": "2026-04-07T16:16:32+00:00",
      "updated": "2026-09-01T12:17:43+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.5.3-11.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-57585",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        416
      ],
      "description": "MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack.  If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed in version 1.2.1.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-57585"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-57585"
        },
        {
          "url": "https://github.com/msgpack/msgpack-python/commit/2c56ddb5d0025ed481d962c0f5d62d19dec7476d"
        },
        {
          "url": "https://github.com/msgpack/msgpack-python/security/advisories/GHSA-6v7p-g79w-8964"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57585"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-57585"
        }
      ],
      "published": "2026-06-30T22:16:57+00:00",
      "updated": "2026-08-06T15:51:03+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "21.3.1-2.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-pip-wheel@21.3.1-2.el9_8?arch=noarch&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-5773",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        488,
        918
      ],
      "description": "libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different \"share\" than the new subsequent transfer\nshould.\n\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5773"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5773"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5773.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-5773.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-rp9q-8q5w-ch44"
        },
        {
          "url": "https://hackerone.com/reports/3650689"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5773"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5773"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-09-15T07:16:28+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58058",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        191
      ],
      "description": "Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffer and the remaining-length computation underflows to a large value. A scanned target or on-path attacker returning a crafted IPv6 response with a truncated extension header can trigger out-of-bounds reads and a crash during raw IPv6 scans.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58058"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58058"
        },
        {
          "url": "https://github.com/bikini/exploitarium/tree/main/nmap-ipv6-extlen-wrap-poc"
        },
        {
          "url": "https://github.com/nmap/nmap/commit/bb6754e76bb1686315008e1aa1c40202a513fb83"
        },
        {
          "url": "https://nmap.org/changelog.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58058"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58058"
        },
        {
          "url": "https://www.vulncheck.com/advisories/nmap-integer-underflow-in-ipv6-extension-header-parsing"
        }
      ],
      "published": "2026-06-28T02:16:33+00:00",
      "updated": "2026-06-30T17:31:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/nmap-ncat@7.92-5.el9?arch=x86_64&distro=redhat-9.8&epoch=3",
          "versions": [
            {
              "version": "3:7.92-5.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/nmap-ncat@7.92-5.el9?arch=x86_64&distro=redhat-9.8&epoch=3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-58470",
      "ratings": [
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-58470"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58470"
        },
        {
          "url": "https://github.com/advisories/GHSA-5f52-px6m-c5hw"
        },
        {
          "url": "https://gitlab.com/gnuwget/wget/-/commit/43d3ba9336bc94937e6fae2365c6ffd30c34ffcf"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58470"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8543-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58470"
        },
        {
          "url": "https://www.vulncheck.com/advisories/gnu-wget-integer-overflow-via-content-range-header-parsing"
        }
      ],
      "published": "2026-07-07T21:17:28+00:00",
      "updated": "2026-07-09T16:01:18+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/wget@1.21.1-11.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.21.1-11.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/wget@1.21.1-11.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-5958",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        367
      ],
      "description": "When sed is invoked with both -i (in-place edit) and --follow-symlinks, the function open_next_file() performs two separate, non-atomic filesystem operations on the same path: \n1. resolves symlink to its target and stores\u00a0the resolved path for determining when output is written,\n2. opens the original symlink path\u00a0(not the resolved one) to read the file. \nBetween these two calls there is a race window. If an attacker atomically replaces the symlink with a different target during that window, sed will: read content from the new (attacker-chosen) symlink target and write the processed result to the path recorded in step 1.\u00a0This can lead to arbitrary file overwrite with attacker-controlled content in the context of the sed process.\n\n\nThis issue was fixed in version 4.10.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-5958"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/05/13/1"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5958"
        },
        {
          "url": "https://cert.pl/en/posts/2026/04/CVE-2026-5958"
        },
        {
          "url": "https://github.com/advisories/GHSA-9r7w-j29g-xqx8"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5958"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8229-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8229-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5958"
        },
        {
          "url": "https://www.gnu.org/software/sed"
        },
        {
          "url": "https://www.gnu.org/software/sed/"
        }
      ],
      "published": "2026-04-20T12:16:08+00:00",
      "updated": "2026-06-17T10:59:56+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.8-10.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-59871",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        704
      ],
      "description": "node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing downstream path handling such as normalizeWindowsPath(entry.path).split('/') to throw an uncaught TypeError. This issue is fixed in version 7.5.18.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59871"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59871"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-59871"
        },
        {
          "url": "https://github.com/advisories/GHSA-w8wr-v893-vjvp"
        },
        {
          "url": "https://github.com/isaacs/node-tar"
        },
        {
          "url": "https://github.com/isaacs/node-tar/commit/e02a4e9e013c4be95302e2eb2047a942b883c27b"
        },
        {
          "url": "https://github.com/isaacs/node-tar/releases/tag/v7.5.18"
        },
        {
          "url": "https://github.com/isaacs/node-tar/security/advisories/GHSA-w8wr-v893-vjvp"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59871"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59871"
        }
      ],
      "published": "2026-07-08T16:16:33+00:00",
      "updated": "2026-07-10T19:02:55+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.34-13.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.34-13.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/tar@1.34-13.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-59875",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        248
      ],
      "description": "node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fixed in version 7.5.17.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59875"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59875"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-59875"
        },
        {
          "url": "https://github.com/advisories/GHSA-gvwx-54wh-qm9j"
        },
        {
          "url": "https://github.com/isaacs/node-tar"
        },
        {
          "url": "https://github.com/isaacs/node-tar/commit/7a635c29f5edbf083557374d43984273ecfed5b3"
        },
        {
          "url": "https://github.com/isaacs/node-tar/releases/tag/v7.5.17"
        },
        {
          "url": "https://github.com/isaacs/node-tar/security/advisories/GHSA-gvwx-54wh-qm9j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59875"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59875"
        }
      ],
      "published": "2026-07-08T16:16:34+00:00",
      "updated": "2026-07-10T19:10:59+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/tar@1.34-13.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2",
          "versions": [
            {
              "version": "2:1.34-13.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/tar@1.34-13.el9_8?arch=x86_64&distro=redhat-9.8&epoch=2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-59890",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        }
      ],
      "cwes": [
        176,
        697
      ],
      "description": "setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0.",
      "recommendation": "Upgrade setuptools to version 83.0.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-59890"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59890"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-59890"
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2026-3447.yaml"
        },
        {
          "url": "https://github.com/pypa/setuptools"
        },
        {
          "url": "https://github.com/pypa/setuptools/commit/dd9f436a36486b4cb8a4c70a2321548b0be09b8f"
        },
        {
          "url": "https://github.com/pypa/setuptools/releases/tag/v83.0.0"
        },
        {
          "url": "https://github.com/pypa/setuptools/security/advisories/GHSA-h35f-9h28-mq5c"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59890"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-59890"
        }
      ],
      "published": "2026-07-08T17:17:27+00:00",
      "updated": "2026-07-13T17:04:58+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/setuptools@70.3.0",
          "versions": [
            {
              "version": "70.3.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:pypi/setuptools@70.3.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. This is a build-time-only sdist-packaging bug requiring a non-default macOS filesystem; CP never builds sdists from untrusted input."
      }
    },
    {
      "id": "CVE-2026-6019",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        150,
        116
      ],
      "description": "http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28247"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6019"
        },
        {
          "url": "https://bugzilla.redhat.com/2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/2460869"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458049"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460869"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4786"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6019"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-28247.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28247"
        },
        {
          "url": "https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c"
        },
        {
          "url": "https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104"
        },
        {
          "url": "https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8"
        },
        {
          "url": "https://github.com/python/cpython/issues/90309"
        },
        {
          "url": "https://github.com/python/cpython/pull/148848"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-6019.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-28581.html"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6019"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8744-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6019"
        }
      ],
      "published": "2026-04-22T20:16:42+00:00",
      "updated": "2026-07-27T17:34:54+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6244",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        369
      ],
      "description": "libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero.  In particular uncommon use cases a crafted filter program can cause a division by zero.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6244"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6244"
        },
        {
          "url": "https://github.com/the-tcpdump-group/libpcap/commit/98bb921b141aa642faedbf2ac510541c76499a19"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6244"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6244"
        }
      ],
      "published": "2026-09-05T19:16:55+00:00",
      "updated": "2026-09-08T19:20:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14",
          "versions": [
            {
              "version": "14:1.10.0-4.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-6253",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        522
      ],
      "description": "curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6253"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/11"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6253"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6253.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6253.json"
        },
        {
          "url": "https://hackerone.com/reports/3669637"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6253"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6253"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-09-15T07:16:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6276",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        346,
        319
      ],
      "description": "Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6276"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/13"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6276"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6276.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6276.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-2jc6-hc33-hv48"
        },
        {
          "url": "https://hackerone.com/reports/3671818"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6276"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6276"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-09-15T07:16:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-63072",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based\non querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive\ncan write and cleanse more bytes than that query reports, causing an 8-byte\nout-of-bounds heap write.\n\nImpact summary: An attacker who supplies a crafted CMS message can trigger a\ndeterministic 8-byte out-of-bounds heap write when the victim decrypts it\nwith CMS_decrypt(), corrupting the heap and typically resulting in a Denial\nof Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: The key-wrap OID is potentially attacker-controlled on the wire.\nCMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.\nAn attacker can take a legitimate message and change a single OID byte to\nselect the padded variant while leaving the message otherwise valid. Since\nthe unwrap key is derived from the recipient's private operation (ECDH key\nagreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot\npass, and the decryption fails with integrity failure.\n\nThe write is a fixed-size (8-byte), fixed-value (zero) heap overflow\nimmediately past the allocation, requires no special configuration, and is\nreachable from the public CMS_decrypt() function. The consequence is\na heap corruption leading to a Denial of Service. The fix in the CMS code\nsizes the unwrap output buffer for the worst case so a failed unwrap cannot\nwrite past the allocation.\n\nFIPS impact: no\n\nAs the CMS code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE.",
      "recommendation": "Upgrade openssl to version 1:3.5.8-1.el9_8; Upgrade openssl-libs to version 1:3.5.8-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63072"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67165"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63072"
        },
        {
          "url": "https://bugzilla.redhat.com/2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/2517570"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517570"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14456"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14457"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18798"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54874"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63072"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63073"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63074"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67165.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67165"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63072.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67165-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63072"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260825.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8865-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63072"
        }
      ],
      "published": "2026-08-25T13:19:26+00:00",
      "updated": "2026-09-11T21:16:34+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-63073",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        134
      ],
      "description": "Issue summary: OpenSSL CMP response validation passed an unexpected response\nsender distinguished name directly as the format string to `ERR_raise_data()`.\n\nImpact summary: A malicious or intercepted CMP endpoint can crash a CMP client\nthat enforces an expected sender or uses a pinned server certificate whose\nsubject becomes the default expected sender.\n\nCWE: CWE-134 (Use of Externally-Controlled Format String)\n\nDescription: When validating a received CMP message, ossl_cmp_msg_check_update()\nconverts the peer-supplied sender distinguished name with X509_NAME_oneline()\nand passes it directly as the format argument to ERR_raise_data(). Percent\ncharacters survive the conversion, so a sender DN such as \"CN=%s%n\" reaches\nBIO_vsnprintf() as an attacker-controlled format string with no matching variadic\narguments. This path is only reached when the caller configures an expected\nsender or pins a server certificate, which is the normal configuration for a\nCMP client validating server responses.\n\nSince the attacker controls the format string but none of the variadic\narguments, such specifiers as %s and %n dereference or write through unrelated\nstack contents and crash the client. The reliable consequence is a denial of\nservice, when the response comes from a malicious or intercepted CMP endpoint.\nThere is no controlled memory write, arbitrary-address read, or reliable path\nto remote code execution.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary.",
      "recommendation": "Upgrade openssl to version 1:3.5.8-1.el9_8; Upgrade openssl-libs to version 1:3.5.8-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63073"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67165"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63073"
        },
        {
          "url": "https://bugzilla.redhat.com/2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/2517570"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517570"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14456"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14457"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18798"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54874"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63072"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63073"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63074"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67165.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67165"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/0cc20b322639919aa423e90799d9a57c3b4b76ca"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/6a0acc072b4d37a7cac1252a29c1ce1f00c5ec29"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7eb2e3ec9d1d4f35c8022fccd4b03398b3f33e21"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a7e5a6eea8fd3ccca6b6fbba031a5fbf8a3d93b4"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63073.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67165-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63073"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260825.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63073"
        }
      ],
      "published": "2026-08-25T13:19:26+00:00",
      "updated": "2026-09-11T21:16:45+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-63074",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches\nadditional certificates (extraCerts) sent in a CMP message, but never expunges\nthem (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX\nfrequently, this cache of extraCerts may grow unboundedly, and a malicious\nclient may flood a CMP server with requests driving this growth.\n\nImpact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX\nfor the lifetime of a server process may observe unbounded memory growth in the\nevent a malicious client repeatedly sends requests containing unique extra\ncertificates, which may lead to OOM conditions.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: If a remote user sends CMP messages to a server with a list of\nextraCerts and the message is rejected, the extraCerts from the message remains\nin the server contexts untrusted certificate stack.  This exposes servers with\nlong lived ctx objects to Denial of Service attacks in which an attacker sends\nmessages intending to be rejected with a large list of additional certificates\nrepeatedly, forcing the server to store them indefinitely.\n   \nThe issue was fixed by removing the added extra certs if the message is\nrejected, using the same method as when the context is configured to not do\ncaching at all.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE.",
      "recommendation": "Upgrade openssl to version 1:3.5.8-1.el9_8; Upgrade openssl-libs to version 1:3.5.8-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63074"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67165"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63074"
        },
        {
          "url": "https://bugzilla.redhat.com/2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/2517570"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517570"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14456"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14457"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18798"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54874"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63072"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63073"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63074"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67165.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67165"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/01e567978a55fba18142a230380c31296049fae7"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/21a5d9658b0c66daace60e10ea18ff32a448de9f"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/74ae7f6df47a5767c1010b88c47507dfc5b32c46"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/75360af9650d4e0c82ba0050c5c9912cd79e54af"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f636f9ca0fa1bae5b42f9e787f025c96fb09c43a"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63074.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67165-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63074"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260825.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63074"
        }
      ],
      "published": "2026-08-25T13:19:26+00:00",
      "updated": "2026-09-11T21:16:58+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-63075",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly\nsends ack-eliciting packets while not acknowledging ACK-only responses, the\nQUIC stack can retain ACK-only packet metadata for the lifetime of the\nconnection.\n\nImpact summary: A remote peer that can complete a QUIC handshake can\ncause connection-scoped memory growth which may lead to Denial of Service\nthrough memory exhaustion, especially with sustained traffic or many concurrent\nQUIC connections.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: When the OpenSSL QUIC stack sends an ACK-only packet,\nthere is no requirement by the QUIC protocol that the peer will acknowledge\nthat ACK-only packet (i.e. it is itself not ack-eliciting). However, the OpenSSL\nimplementation stores the metadata about the ACK frames regardless.\nIn and of itself that's ok, but if a malicious peer establishes a connection, and\nthen drives the connection such that ACK-only packets are forced from the \nOpenSSL implementation peer (i.e., by sending numerous PING frames),\nand then withholding any subsequent acks for ack-eliciting data, like\nlegitimate data, said malicious peer can force inappropriate memory growth\non the OpenSSL peer, potentially leading to a Denial of Service.\n\nThe fix is to ensure that we account for the transmission of the ACK-only\npacket in the packet histories high and low watermark without actually storing\nthe ACK-only packet metadata itself.\n\nFIPS impact: no\nThe OpenSSL FIPS module is not affected as the QUIC code is\noutside the FIPS module boundary.",
      "recommendation": "Upgrade openssl to version 1:3.5.8-1.el9_8; Upgrade openssl-libs to version 1:3.5.8-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63075"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67165"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63075"
        },
        {
          "url": "https://bugzilla.redhat.com/2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/2517570"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517570"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14456"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14457"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18798"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54874"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63072"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63073"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63074"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67165.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67165"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7308946576b12e64b8be53bcf0a120354b2b42bc"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7c98d79738549df92868e7dd9be4bbf061eed709"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/bf84721c2548351176e367e6de505792f0118dc6"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/c902e5f16d6a9e130e96d3ca6d8f64d71652e393"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63075.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67165-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63075"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260825.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63075"
        }
      ],
      "published": "2026-08-25T13:19:26+00:00",
      "updated": "2026-09-11T21:17:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-63076",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: OpenSSL CMP password based protection verification only\nchecks whether the protectionAlg parameter was not NULL and not its\nASN.1 type, before treating it as a PBMParameter. A crafted message can\ncontain a parameter of a different type, which is then dereferenced as an\ninvalid pointer.\n\nImpact summary: A remote, unauthenticated attacker can crash an application\nacting as a CMP server that accepts PBM-protected messages, or a CMP client\ntalking to a malicious or intercepted CMP server, resulting in a Denial of\nService.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: When verifying the password-based MAC protection of a CMP\nmessage, OpenSSL library reads the protectionAlg algorithm parameter with\nX509_ALGOR_get0(), which returns both the parameter type and its value\npointer. The value is then cast to an ASN1_STRING and treated as the\nexpected PBMParameter after only checking that pointer is not NULL. The\nparameter type returned by X509_ALGOR_get0() was never consulted.\n\nThis happens during protection verification, before any MAC is computed, so\nno knowledge of the PBM shared secret is required; the only precondition is\nthat PBM verification is reachable. On the server side this is reached from\nOSSL_CMP_SRV_process_request() for any application that stands up a CMP\nserver accepting PBM-protected messages, and on the client side from CMP\nresponse validation against a malicious or on-path (MITM) server. The\nreliable consequence is a denial of service; there is no memory disclosure,\nno controlled memory write, and no path to code execution. CMP is a\nspecialized feature that an application must explicitly enable.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE.",
      "recommendation": "Upgrade openssl to version 1:3.5.8-1.el9_8; Upgrade openssl-libs to version 1:3.5.8-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63076"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67165"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63076"
        },
        {
          "url": "https://bugzilla.redhat.com/2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/2517570"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515348"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517559"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517560"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517561"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517562"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517564"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517565"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517566"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517570"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14456"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14457"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18798"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54874"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63072"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63073"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63074"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63075"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63076"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67165.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67165"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/37882aa2e0256e1072442a8f62f7db45b995c45b"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a17cc8d612ecff6d94a9b7ca8b5283ddf5ff570e"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a1f348ccb328c3afbd4ba6883f9b7c813c043259"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a7af46a92d0ce19a90e669ef56d2576a07924226"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/cdacfff557389abfa9e4615abded2ec984517d6c"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63076.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67165-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63076"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260825.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8865-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63076"
        }
      ],
      "published": "2026-08-25T13:19:26+00:00",
      "updated": "2026-09-11T21:17:12+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-63379",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        444
      ],
      "description": "Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent processes chunked HTTP trailers in http.c through evhttp_read_trailer and merges them into request headers. The fix introduces evhttp_parse_headers_impl_ and a temporary trailer header list. An unauthenticated remote attacker can place security-sensitive fields in trailers so that an upstream proxy and the libevent application interpret different effective headers, enabling header smuggling, authorization bypass, proxy-header spoofing, or cache poisoning. The fix parses trailers into a temporary header list and discards them instead of merging them into req->input_headers. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.",
      "recommendation": "Upgrade libevent to version 2.1.13-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63379"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67910"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63379"
        },
        {
          "url": "https://bugzilla.redhat.com/2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/2520667"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520660"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520667"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63379"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63381"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63382"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63384"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63385"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63387"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63388"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67910.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67910"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/87e8e44fa774e9677b089b1a5114ee68aefa1636"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/b847071141b3827900d536594ec9045eb0a4c485"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"
        },
        {
          "url": "https://github.com/libevent/libevent/security/advisories/GHSA-2gmv-p5m7-98p6"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63379.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67910.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63379"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63379"
        }
      ],
      "published": "2026-08-20T18:16:35+00:00",
      "updated": "2026-09-09T21:19:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.1.12-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-63381",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        908
      ],
      "description": "Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_reference processes an output buffer whose out_total_len is zero. evbuffer_free_all_chains frees the initial empty chain without resetting outbuf->first, outbuf->last, or outbuf->last_with_datap, and APPEND_CHAIN_MULTICAST subsequently dereferences the dangling chain pointer. A caller that can drive this buffer state can cause memory corruption or a process crash. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.",
      "recommendation": "Upgrade libevent to version 2.1.13-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63381"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67910"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63381"
        },
        {
          "url": "https://bugzilla.redhat.com/2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/2520667"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520660"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520667"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63379"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63381"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63382"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63384"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63385"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63387"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63388"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67910.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67910"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/5cb95ba2f804f8aff46f88d58391c71e1251cd1c"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/9db091b04f569be3a700fa9860ef02f90b830af9"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"
        },
        {
          "url": "https://github.com/libevent/libevent/security/advisories/GHSA-c2pj-cg4r-88c8"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63381.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67910.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63381"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8710-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63381"
        }
      ],
      "published": "2026-08-20T18:16:35+00:00",
      "updated": "2026-09-09T21:19:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.1.12-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-63382",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.7,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        444
      ],
      "description": "Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Transfer-Encoding headers, comma-separated Transfer-Encoding values, and bare line feeds in chunked framing. evhttp_find_header can select only the first header, evhttp_check_transfer_encoding_ was absent so the previous whole-string comparison fails to recognize valid lists ending in chunked, and evhttp_handle_chunked_read uses EVBUFFER_EOL_CRLF rather than EVBUFFER_EOL_CRLF_STRICT, accepting bare LF chunk terminators. When libevent is deployed behind a proxy that frames the same request differently, an unauthenticated remote attacker can desynchronize request boundaries and smuggle a second request, potentially bypassing access controls or poisoning caches. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.",
      "recommendation": "Upgrade libevent to version 2.1.13-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63382"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67910"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63382"
        },
        {
          "url": "https://bugzilla.redhat.com/2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/2520667"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520660"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520667"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63379"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63381"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63382"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63384"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63385"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63387"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63388"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67910.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67910"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/10abb34b8dc3e1184de315dd261ce4b77563cda6"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/5119ceb00557bf007f9065709e852686f3c0bb6e"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/83ba67373032334559b82409db035dd8c3cc1660"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/ac38703b2d312200c4f967f02936af0118d384a0"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"
        },
        {
          "url": "https://github.com/libevent/libevent/security/advisories/GHSA-q39v-w2g7-gr8j"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63382.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67910.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63382"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8710-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63382"
        }
      ],
      "published": "2026-08-20T18:16:35+00:00",
      "updated": "2026-09-09T21:19:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.1.12-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-63383",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in event_tagging.c when decode_tag_internal requests at most five bytes from evbuffer_pullup but iterates using the full logical buffer length. A fragmented evbuffer containing a six-byte malformed tag can therefore advance past the pullup window and trigger an out-of-bounds read, which can crash a process that decodes attacker-controlled tagged RPC data. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.",
      "recommendation": "Upgrade libevent to version 2.1.13-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63383"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67910"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63383"
        },
        {
          "url": "https://bugzilla.redhat.com/2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/2520667"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520660"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520667"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63379"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63381"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63382"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63384"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63385"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63387"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63388"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67910.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67910"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/91ed8745eebabdd27592a83d350338a8c4626321"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/e1f9e21887c6b104e206a718385ba3ffc75180cb"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"
        },
        {
          "url": "https://github.com/libevent/libevent/security/advisories/GHSA-fj29-64w6-73h6"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63383.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67910.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63383"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8710-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63383"
        }
      ],
      "published": "2026-08-20T18:16:35+00:00",
      "updated": "2026-09-09T21:19:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.1.12-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-63384",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evtag_unmarshal_header uses evtag_decode_int to decode an attacker-controlled uint32 payload length and returns it as a signed int. Values above INT_MAX become negative or truncated, and evtag_unmarshal_string can use the converted value in allocation sizing, producing a wrapped large allocation request and denial of service. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.",
      "recommendation": "Upgrade libevent to version 2.1.13-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63384"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67910"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63384"
        },
        {
          "url": "https://bugzilla.redhat.com/2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/2520667"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520660"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520667"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63379"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63381"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63382"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63384"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63385"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63387"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63388"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67910.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67910"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/109c16499282959d70f56ec3baf4c8b1e6646bda"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/5e3c6ebe342b34c5a9bcf48e9a32ad6708b9c416"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"
        },
        {
          "url": "https://github.com/libevent/libevent/security/advisories/GHSA-45c6-qx49-89m8"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63384.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67910.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63384"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8710-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63384"
        }
      ],
      "published": "2026-08-20T18:16:36+00:00",
      "updated": "2026-09-09T21:19:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.1.12-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-63385",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.7,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        444
      ],
      "description": "Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_internal decodes percent-encoded %00 bytes into literal NUL characters, which can cause downstream C string operations to truncate a path and bypass validation performed on a different representation. evhttp_header_is_valid_value also accepts obsolete line folding in header values containing carriage return or line feed characters, allowing a proxy and libevent to interpret headers differently and enabling header injection or access control bypass. The CRLF header acceptance is fixed in versions 2.1.13 and 2.2.2-alpha, but the reviewed patches do not clearly remediate the URI NUL-truncation condition.",
      "recommendation": "Upgrade libevent to version 2.1.13-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63385"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67910"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63385"
        },
        {
          "url": "https://bugzilla.redhat.com/2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/2520667"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520660"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520667"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63379"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63381"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63382"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63384"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63385"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63387"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63388"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67910.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67910"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/758be0c0f69c1934ef9a84ab39e9f9e5fde2e6d0"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/9170dd35e64714613e8d13b290587cfc28e258e2"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"
        },
        {
          "url": "https://github.com/libevent/libevent/security/advisories/GHSA-jcwh-pvf2-73p2"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63385.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67910.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63385"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8710-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63385"
        }
      ],
      "published": "2026-08-20T18:16:36+00:00",
      "updated": "2026-09-09T21:19:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.1.12-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-63387",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.6,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121,
        193,
        787
      ],
      "description": "Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_to_labels formats a name-bearing DNS record at the end of the 64 KB stack buffer allocated by evdns_server_request_format_response. The final-label check permits j plus label_len plus one to equal buf_len, after which the terminating null byte is written to buf[buf_len]. A crafted DNS server response containing PTR, CNAME, MX, NS, or SOA data can trigger the one-byte out-of-bounds write and crash or corrupt the process. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.",
      "recommendation": "Upgrade libevent to version 2.1.13-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67910"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63387"
        },
        {
          "url": "https://bugzilla.redhat.com/2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/2520667"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520660"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520667"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63379"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63381"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63382"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63384"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63385"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63387"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63388"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67910.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67910"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"
        },
        {
          "url": "https://github.com/libevent/libevent/security/advisories/GHSA-58rx-7448-jw47"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63387.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67910.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63387"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8840-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63387"
        }
      ],
      "published": "2026-08-20T18:16:36+00:00",
      "updated": "2026-09-09T21:19:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.1.12-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-63388",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        617,
        787
      ],
      "description": "Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in bufferevent_sock.c when bufferevent_socket_set_conn_address_ copies a kernel-supplied AF_UNIX peer address into bufferevent_private.conn_address. Release builds compiled with NDEBUG disable the EVUTIL_ASSERT length guard, and the evhttp accept path can pass a 110-byte sockaddr from accept() into the 28-byte field. An unauthenticated local peer able to connect to an AF_UNIX listener can overwrite the adjacent dns_request pointer and heap data, causing memory corruption with confidentiality, integrity, and availability impact. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.",
      "recommendation": "Upgrade libevent to version 2.1.13-1.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-63388"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67910"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-63388"
        },
        {
          "url": "https://bugzilla.redhat.com/2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/2520667"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520654"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520655"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520657"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520658"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520660"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520661"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520666"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2520667"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63379"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63381"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63382"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63383"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63384"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63385"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63387"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63388"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-67910.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:67910"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/52057cb33d0c20c0a0453fbabe6c0c96854931b9"
        },
        {
          "url": "https://github.com/libevent/libevent/commit/ef38f926e9cd1f082416c6fff13587bc1f431d72"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable"
        },
        {
          "url": "https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"
        },
        {
          "url": "https://github.com/libevent/libevent/security/advisories/GHSA-cvq5-vrvr-j338"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-63388.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-67910.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63388"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8840-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63388"
        }
      ],
      "published": "2026-08-20T18:16:36+00:00",
      "updated": "2026-09-09T21:19:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.1.12-8.el9_4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libevent@2.1.12-8.el9_4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-6368",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        908
      ],
      "description": "Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43\u00a0can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.",
      "recommendation": "Upgrade glibc to version 2.34-283.el9_8; Upgrade glibc-common to version 2.34-283.el9_8; Upgrade glibc-minimal-langpack to version 2.34-283.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6368"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:76777"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6368"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2513603"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2513608"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6368"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6791"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2026-76777.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:76777"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6368"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34090"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6368"
        }
      ],
      "published": "2026-08-10T19:17:30+00:00",
      "updated": "2026-09-03T16:43:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-6429",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        200
      ],
      "description": "When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6429"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6429"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6429.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-6429.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-2pvc-5qw9-h3ph"
        },
        {
          "url": "https://hackerone.com/reports/3677759"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6429"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6429"
        }
      ],
      "published": "2026-05-13T13:01:56+00:00",
      "updated": "2026-09-15T07:16:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-6554",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        835
      ],
      "description": "libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as a signed integer to implement looping via backward jumps, but it does not limit the number of loop iterations.  In particular uncommon use cases a crafted filter program can cause the interpreter to loop infinitely.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6554"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6554"
        },
        {
          "url": "https://github.com/the-tcpdump-group/libpcap/commit/ff3c83475ac303c6b681c52ad0b6e14795a8e0ce"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6554"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6554"
        }
      ],
      "published": "2026-09-05T19:16:56+00:00",
      "updated": "2026-09-08T19:20:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14",
          "versions": [
            {
              "version": "14:1.10.0-4.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libpcap@1.10.0-4.el9?arch=x86_64&distro=redhat-9.8&epoch=14"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-66046",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        407
      ],
      "description": "Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options.",
      "recommendation": "Upgrade expat to version 2.5.0-6.el9_8.5",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-66046"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72663"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-66046"
        },
        {
          "url": "https://bugzilla.redhat.com/2538967"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517901"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2538967"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-66046"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-93990"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-72663.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:72663"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1321"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-66046.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-74001.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66046"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8813-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-66046"
        },
        {
          "url": "https://www.vulncheck.com/advisories/expat-denial-of-service-via-storeatts-quadratic-complexity"
        }
      ],
      "published": "2026-08-18T15:16:57+00:00",
      "updated": "2026-09-18T15:07:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-67693",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "description": "An issue in gnutls v.3.8.13 allows an attacker to obtain sensitive information via failing to reject end-entity X.509 certificates that contain a contradictory combination of Key Usage (KU) and Extended Key Usage (EKU)",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-67693"
        },
        {
          "url": "http://gnutls.com"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-67693"
        },
        {
          "url": "https://gist.github.com/lkloliver/6fbfc191bc6163942c8017551ac3f238"
        },
        {
          "url": "https://gitlab.com/gnutls/gnutls/-/blob/3.8.13/lib/x509/verify.c#L1119-1178"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67693"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-67693"
        }
      ],
      "published": "2026-10-08T19:18:41+00:00",
      "updated": "2026-10-08T21:33:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.8.10-8.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-6791",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121
      ],
      "description": "When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.",
      "recommendation": "Upgrade glibc to version 2.34-283.el9_8; Upgrade glibc-common to version 2.34-283.el9_8; Upgrade glibc-minimal-langpack to version 2.34-283.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-6791"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:76777"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6791"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2513603"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2513608"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6368"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6791"
        },
        {
          "url": "https://errata.almalinux.org/8/ALSA-2026-76777.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:76777"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6791"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34091"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0013"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6791"
        }
      ],
      "published": "2026-08-10T19:17:30+00:00",
      "updated": "2026-09-03T16:43:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-7168",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        294
      ],
      "description": "Successfully using libcurl to do a transfer over a specific HTTP proxy\n(`proxyA`) with **Digest** authentication and then changing the proxy host to\na second one (`proxyB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Proxy-Authorization:` header field meant for\n`proxyA`, to `proxyB`.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-7168"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/14"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-7168"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-7168.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-7168.json"
        },
        {
          "url": "https://github.com/advisories/GHSA-v92m-hrhj-gw54"
        },
        {
          "url": "https://hackerone.com/reports/3697719"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7168"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8227-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8525-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7168"
        }
      ],
      "published": "2026-05-13T13:01:57+00:00",
      "updated": "2026-09-15T07:16:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-7210",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        331
      ],
      "description": "`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-7210"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/05/11/13"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/05/11/8"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-7210"
        },
        {
          "url": "https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4"
        },
        {
          "url": "https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566"
        },
        {
          "url": "https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56"
        },
        {
          "url": "https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b"
        },
        {
          "url": "https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286"
        },
        {
          "url": "https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a"
        },
        {
          "url": "https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f"
        },
        {
          "url": "https://github.com/python/cpython/issues/149018"
        },
        {
          "url": "https://github.com/python/cpython/pull/149023"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7210"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7210"
        }
      ],
      "published": "2026-05-11T18:16:42+00:00",
      "updated": "2026-10-02T01:16:44+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-72712",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        835
      ],
      "description": "Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a crafted packet containing a zero-length TCP option. The malformed packet forces the Packet:parse_options() function in nselib/packet.lua to allocate objects in an infinite loop, causing an out-of-memory condition that results in application crash.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-72712"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-72712"
        },
        {
          "url": "https://github.com/nmap/nmap"
        },
        {
          "url": "https://github.com/nmap/nmap/commit/7ef4ee030a0023fe22616387a000032e1a678b6a"
        },
        {
          "url": "https://github.com/nmap/nmap/issues/3368"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-72712"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72712"
        },
        {
          "url": "https://www.vulncheck.com/advisories/nmap-denial-of-service-via-zero-length-tcp-option-packet"
        }
      ],
      "published": "2026-08-11T18:18:23+00:00",
      "updated": "2026-09-24T20:30:25+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/nmap-ncat@7.92-5.el9?arch=x86_64&distro=redhat-9.8&epoch=3",
          "versions": [
            {
              "version": "3:7.92-5.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/nmap-ncat@7.92-5.el9?arch=x86_64&distro=redhat-9.8&epoch=3"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-72897",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        787
      ],
      "description": "Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-72897"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-72897"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-72897"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72897"
        }
      ],
      "published": "2026-09-29T16:17:09+00:00",
      "updated": "2026-10-08T01:19:41+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-74860",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        763
      ],
      "description": "A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.",
      "recommendation": "Upgrade libxml2 to version 2.9.13-14.el9_8.5",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-74860"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:64463"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71585"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71586"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71641"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72470"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72475"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72476"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:79357"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-74860"
        },
        {
          "url": "https://bugzilla.redhat.com/2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/2529697"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2529697"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-74860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86138"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86140"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86142"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86143"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86144"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-71585.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:71585"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-74860.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-71641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-74860"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8787-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-74860"
        }
      ],
      "published": "2026-09-08T12:16:58+00:00",
      "updated": "2026-10-09T02:17:04+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-75803",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        354
      ],
      "description": "Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-75803"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-75803"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/bf95f5f772e9362f87b25cfa2f8cb15d984865b9"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75803"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260825.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8678-3"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8865-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75803"
        }
      ],
      "published": "2026-08-25T13:19:29+00:00",
      "updated": "2026-09-11T21:17:17+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-75804",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-75804"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-75804"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75804"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75804"
        }
      ],
      "published": "2026-09-29T16:17:10+00:00",
      "updated": "2026-10-08T01:20:01+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-75805",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        476
      ],
      "description": "Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-75805"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-75805"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75805"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75805"
        }
      ],
      "published": "2026-09-29T16:17:11+00:00",
      "updated": "2026-10-08T01:20:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-75806",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        1284
      ],
      "description": "Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-75806"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-75806"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75806"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75806"
        }
      ],
      "published": "2026-09-29T16:17:11+00:00",
      "updated": "2026-10-08T01:20:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-76641",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch between ELEMENT_TYPE members causes storeAtts to read the attIndex member past allocated memory boundaries, resulting in failure to normalize whitespace in non-CDATA attributes or a wild pointer dereference causing a segfault. This vulnerability was introduced by the fix for CVE-2026-66046.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-76641"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-76641"
        },
        {
          "url": "https://github.com/libexpat/libexpat/commit/98599f6dcc2b460410881fe420f5f55d6bec63bf"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1331"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76641"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8813-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-76641"
        },
        {
          "url": "https://www.vulncheck.com/advisories/expat-out-of-bounds-read-via-dtdcopy"
        }
      ],
      "published": "2026-08-20T18:16:51+00:00",
      "updated": "2026-09-24T20:02:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-76957",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        416
      ],
      "description": "libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-76957"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-76957"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1322"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1329"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76957"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8813-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-76957"
        }
      ],
      "published": "2026-08-20T05:16:29+00:00",
      "updated": "2026-09-08T20:56:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-77117",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        835
      ],
      "description": "Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489.",
      "recommendation": "Upgrade glibc to version 2.34-283.el9_8; Upgrade glibc-common to version 2.34-283.el9_8; Upgrade glibc-minimal-langpack to version 2.34-283.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-77117"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-77117"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77117"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34556"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-77117"
        }
      ],
      "published": "2026-09-15T11:17:12+00:00",
      "updated": "2026-09-18T18:17:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-77214",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L"
        }
      ],
      "cwes": [
        125
      ],
      "description": "libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-77214"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-77214"
        },
        {
          "url": "https://github.com/libexpat/libexpat/commit/13c5f63a7f1c52c2feee3b16a1134d4fb68e9ea0"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1393"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77214"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-77214"
        },
        {
          "url": "https://www.vulncheck.com/advisories/libexpat-heap-buffer-over-read-in-xmlparse-c-via-xml-parsebuffer"
        }
      ],
      "published": "2026-10-07T15:17:53+00:00",
      "updated": "2026-10-07T15:57:20+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-77696",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        208
      ],
      "description": "Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-77696"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-77696"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77696"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-77696"
        }
      ],
      "published": "2026-09-29T16:17:11+00:00",
      "updated": "2026-10-08T01:20:41+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-7774",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        22
      ],
      "description": "tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-7774"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/06/04/9"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-7774"
        },
        {
          "url": "https://github.com/python/cpython/commit/0478bd83d82b255e0f29f613367a59d261e7eaa2"
        },
        {
          "url": "https://github.com/python/cpython/commit/0d28f5e46e151718972dfabd91205444d0037b6d"
        },
        {
          "url": "https://github.com/python/cpython/commit/10a13bee3c24f9c62b602e696334ff2272a40efc"
        },
        {
          "url": "https://github.com/python/cpython/commit/578411982c16f753f4893532510099ef665117da"
        },
        {
          "url": "https://github.com/python/cpython/commit/5cf47a248c35c375d610b87b2f72fd1ed454b558"
        },
        {
          "url": "https://github.com/python/cpython/commit/74cca9a92fb7d653e404843a56b8bdc7b0afdbbf"
        },
        {
          "url": "https://github.com/python/cpython/commit/c063191cb7f9170f9565e305f8aa2b79ab2bf609"
        },
        {
          "url": "https://github.com/python/cpython/issues/149486"
        },
        {
          "url": "https://github.com/python/cpython/pull/149487"
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/4FU62L2M6RMMHT2QPGQNPEHHUND7CEX5/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7774"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8509-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7774"
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/06/04/9"
        }
      ],
      "published": "2026-06-04T16:16:42+00:00",
      "updated": "2026-08-13T01:16:55+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.9.25-7.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python-unversioned-command@3.9.25-7.el9_8.3?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-libs@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3@3.9.25-7.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-78367",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        94
      ],
      "description": "A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:...} macro expression. A specially crafted .spec member name can therefore inject RPM macros, including Lua expressions, resulting in arbitrary code execution with the privileges of the user running rpmbuild. This can be exploited when a victim or automated build system processes an attacker-controlled source tarball using rpmbuild tarball mode (such as -ts, -ta, or -tb).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-78367"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-78367"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2521857"
        },
        {
          "url": "https://github.com/rpm-software-management/rpm/issues/4314"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78367"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-78367"
        }
      ],
      "published": "2026-08-24T14:17:04+00:00",
      "updated": "2026-09-04T12:17:19+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The vulnerable rpmbuild tarball-mode code path is never invoked by CP; rpm/python3-rpm are base-image package-manager components only."
      }
    },
    {
      "id": "CVE-2026-80230",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        295
      ],
      "description": "When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-80230"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-80230"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-80230.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-80230.json"
        },
        {
          "url": "https://github.com/curl/curl/commit/5267ed859d545534d0c21"
        },
        {
          "url": "https://hackerone.com/reports/3969300"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80230"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8820-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-80230"
        }
      ],
      "published": "2026-09-06T18:17:22+00:00",
      "updated": "2026-09-15T07:16:30+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-80489",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        835
      ],
      "description": "Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117.",
      "recommendation": "Upgrade glibc to version 2.34-283.el9_8; Upgrade glibc-common to version 2.34-283.el9_8; Upgrade glibc-minimal-langpack to version 2.34-283.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-80489"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-80489"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80489"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34568"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8737-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-80489"
        }
      ],
      "published": "2026-09-15T11:17:12+00:00",
      "updated": "2026-09-18T18:17:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-82209",
      "ratings": [
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        201
      ],
      "description": "When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-82209"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-82209"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-82209.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-82209.json"
        },
        {
          "url": "https://github.com/curl/curl/commit/95c1e8915dce64606bd753fd47f"
        },
        {
          "url": "https://hackerone.com/reports/3972385"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82209"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8820-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-82209"
        }
      ],
      "published": "2026-09-06T18:17:22+00:00",
      "updated": "2026-09-15T07:16:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-82327",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        129
      ],
      "description": "A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache files. When libsolv rewrites a .solv cache file, it reads directory-id values from the file's compressed filelist data without validating that they fall within the expected range. A corrupted or specially crafted .solv cache file (for example, one left in a torn state after an unclean system shutdown) can cause an out-of-bounds memory write when a tool such as dnf, yum, or zypper next processes it. Successful exploitation is expected to result in a crash of the affected tool (denial of service); it is not expected to allow arbitrary code execution because the out-of-bounds write always stores a fixed, non-attacker-controlled value.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-82327"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-82327"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2525602"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82327"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-82327"
        }
      ],
      "published": "2026-08-28T16:18:34+00:00",
      "updated": "2026-08-28T20:20:21+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.7.24-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-8458",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        488
      ],
      "description": "libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n\"services\".\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services.",
      "recommendation": "Upgrade curl-minimal to version 7.76.1-40.el9_8.7; Upgrade libcurl-minimal to version 7.76.1-40.el9_8.7",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8458"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69126"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8458"
        },
        {
          "url": "https://bugzilla.redhat.com/2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/2496769"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496769"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8458.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8458.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8458.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8458"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8927"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-69126.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69126"
        },
        {
          "url": "https://github.com/advisories/GHSA-88c6-6jfq-mm4q"
        },
        {
          "url": "https://hackerone.com/reports/3721183"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-8458.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-69126.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8458"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8458"
        }
      ],
      "published": "2026-07-03T07:16:24+00:00",
      "updated": "2026-09-15T07:16:32+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-84782",
      "ratings": [
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary.",
      "recommendation": "Upgrade openssl to version 1:3.5.8-2.el9_8; Upgrade openssl-libs to version 1:3.5.8-2.el9_8",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-84782"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:76918"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-84782"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2537080"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84782"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:76918"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58"
        },
        {
          "url": "https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-84782.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-77396.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84782"
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        },
        {
          "url": "https://openssl-library.org/news/vulnerabilities/#CVE-2026-84782"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8847-2"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-84782"
        }
      ],
      "published": "2026-09-29T16:17:12+00:00",
      "updated": "2026-10-08T01:20:56+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1",
          "versions": [
            {
              "version": "1:3.5.5-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl-libs@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/openssl@3.5.5-6.el9_8?arch=x86_64&distro=redhat-9.8&epoch=1"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-84837",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        78
      ],
      "description": "A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with the privileges of the build user, which could lead to information disclosure or disruption of the build environment.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-84837"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-84837"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2478408"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84837"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-84837"
        }
      ],
      "published": "2026-09-02T16:17:33+00:00",
      "updated": "2026-09-03T18:12:56+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-86138",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.",
      "recommendation": "Upgrade libxml2 to version 2.9.13-14.el9_8.5",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-86138"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71585"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-86138"
        },
        {
          "url": "https://bugzilla.redhat.com/2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/2529697"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2529697"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-74860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86138"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86140"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86142"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86143"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86144"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-71585.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:71585"
        },
        {
          "url": "https://github.com/GNOME/libxml2/commit/a4cba4b5b5a8c42e155ed42d2d2a44955465a2e4"
        },
        {
          "url": "https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-86138.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-71641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86138"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8910-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-86138"
        }
      ],
      "published": "2026-09-05T05:17:12+00:00",
      "updated": "2026-09-15T19:40:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-86140",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121
      ],
      "description": "In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.",
      "recommendation": "Upgrade libxml2 to version 2.9.13-14.el9_8.5",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-86140"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71585"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-86140"
        },
        {
          "url": "https://bugzilla.redhat.com/2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/2529697"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2529697"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-74860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86138"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86140"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86142"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86143"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86144"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-71585.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:71585"
        },
        {
          "url": "https://github.com/GNOME/libxml2/commit/d1686f91dbda141a752200419d35639fd6b38340"
        },
        {
          "url": "https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-86140.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-71641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86140"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8787-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-86140"
        }
      ],
      "published": "2026-09-05T05:17:12+00:00",
      "updated": "2026-09-15T19:39:17+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-86142",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.",
      "recommendation": "Upgrade libxml2 to version 2.9.13-14.el9_8.5",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-86142"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71585"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-86142"
        },
        {
          "url": "https://bugzilla.redhat.com/2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/2529697"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2529697"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-74860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86138"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86140"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86142"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86143"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86144"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-71585.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:71585"
        },
        {
          "url": "https://github.com/GNOME/libxml2/commit/6b3a736c0edc74ceec3d82f5252499d7911b3a58"
        },
        {
          "url": "https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1113"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-86142.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-71586.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86142"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8910-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-86142"
        }
      ],
      "published": "2026-09-05T05:17:13+00:00",
      "updated": "2026-09-15T19:35:48+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-86143",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.3,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        192
      ],
      "description": "In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.",
      "recommendation": "Upgrade libxml2 to version 2.9.13-14.el9_8.5",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-86143"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71585"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-86143"
        },
        {
          "url": "https://bugzilla.redhat.com/2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/2529697"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2529697"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-74860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86138"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86140"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86142"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86143"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86144"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-71585.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:71585"
        },
        {
          "url": "https://github.com/GNOME/libxml2/commit/90f293ba74d28b1d570920382e707586f68ebf35"
        },
        {
          "url": "https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1111"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-86143.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-71641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86143"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8910-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-86143"
        }
      ],
      "published": "2026-09-05T05:17:13+00:00",
      "updated": "2026-09-15T19:31:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-86144",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.6,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        669
      ],
      "description": "In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).",
      "recommendation": "Upgrade libxml2 to version 2.9.13-14.el9_8.5",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-86144"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:71585"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-86144"
        },
        {
          "url": "https://bugzilla.redhat.com/2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/2529697"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528986"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528987"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528989"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528990"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528992"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2529697"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-74860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86138"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86140"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86142"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86143"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86144"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-71585.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:71585"
        },
        {
          "url": "https://github.com/GNOME/libxml2/commit/b63cd517afecb76582dd9488c55e54ceaf50de61"
        },
        {
          "url": "https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-86144.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-71641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86144"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8910-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-86144"
        }
      ],
      "published": "2026-09-05T05:17:13+00:00",
      "updated": "2026-09-15T19:20:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.9.13-14.el9_8.4",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.4?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-86145",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        424
      ],
      "description": "PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-86145"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/09/05/3"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-86145"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86145"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-86145"
        }
      ],
      "published": "2026-09-05T06:17:10+00:00",
      "updated": "2026-09-09T16:04:24+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-86469",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        59
      ],
      "description": "A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-86469"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-86469"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2473839"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/blob/main/gio/glocalfileoutputstream.c"
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/work_items/4044"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86469"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-86469"
        }
      ],
      "published": "2026-09-07T16:17:30+00:00",
      "updated": "2026-09-08T19:08:15+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.68.4-19.el9_8.10",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-8674",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        617
      ],
      "description": "Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8674"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/09/17/4"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8674"
        },
        {
          "url": "https://joshua.hu/fuzzing-glibc-libresolv"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8674"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=31026"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8674"
        }
      ],
      "published": "2026-09-17T17:16:53+00:00",
      "updated": "2026-09-18T18:17:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-86805",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        367
      ],
      "description": "A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-86805"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-86805"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86805"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34360"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-86805"
        }
      ],
      "published": "2026-09-22T16:18:06+00:00",
      "updated": "2026-09-23T04:17:57+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-88647",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "description": "A hostname verification bypass in GnuTLS v3.8.13 allows attackers to circumvent the Common Name fallback mechanism and eavesdrop on communications via a crafted certificate.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-88647"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-88647"
        },
        {
          "url": "https://gist.github.com/lkloliver/f98ec3de1a871fdfc02b70b8b9ba7642"
        },
        {
          "url": "https://gitlab.com/gnutls/gnutls/-/issues/1802"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-88647"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-88647"
        }
      ],
      "published": "2026-10-08T17:17:17+00:00",
      "updated": "2026-10-08T21:33:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.8.10-8.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-88648",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "description": "Incomplete X.509 implementation in GnuTLS v3.8.13 allows attackers controlling a subordinate Certificate Authority to bypass cross-domain PKI restrictions and issue unauthorized certificates.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-88648"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-88648"
        },
        {
          "url": "https://gist.github.com/lkloliver/1f2a97cb8d0b31aa27b6bd0354358d7d"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-88648"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-88648"
        },
        {
          "url": "https://www.rfc-editor.org/rfc/rfc5280#section-4.2.1.10"
        },
        {
          "url": "https://www.rfc-editor.org/rfc/rfc5280#section-6.1.4"
        }
      ],
      "published": "2026-10-08T19:20:52+00:00",
      "updated": "2026-10-08T21:33:42+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "3.8.10-8.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/gnutls@3.8.10-8.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ]
    },
    {
      "id": "CVE-2026-88806",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-88806"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-88806"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/309"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-88806"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-88806"
        }
      ],
      "published": "2026-09-21T14:17:22+00:00",
      "updated": "2026-09-22T19:40:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.8.12-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.8.12-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-88807",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.3,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A heap overflow in libXrender before 0.9.13 in\u00a0RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-88807"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-88807"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxrender/-/merge_requests/19"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-88807"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-88807"
        }
      ],
      "published": "2026-09-21T14:17:22+00:00",
      "updated": "2026-09-22T19:40:05+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libXrender@0.9.10-16.el9_8.1?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.9.10-16.el9_8.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libXrender@0.9.10-16.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libXrender@0.9.10-16.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libXrender@0.9.10-16.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libXrender@0.9.10-16.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libXrender@0.9.10-16.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libXrender@0.9.10-16.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libXrender@0.9.10-16.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libXrender@0.9.10-16.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libXrender@0.9.10-16.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libXrender@0.9.10-16.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libXrender@0.9.10-16.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libXrender@0.9.10-16.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libXrender@0.9.10-16.el9_8.1?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libXrender@0.9.10-16.el9_8.1?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-89092",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.2,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        789
      ],
      "description": "The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.\u00a0 During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.\u00a0 In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-89092"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/09/11/2"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-89092"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89092"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34624"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0016"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-89092"
        }
      ],
      "published": "2026-09-11T02:18:35+00:00",
      "updated": "2026-09-11T18:17:00+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-89156",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 2.9,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        125
      ],
      "description": "PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-89156"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-89156"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89156"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-89156"
        }
      ],
      "published": "2026-09-11T04:18:03+00:00",
      "updated": "2026-09-16T19:27:01+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-89157",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-89157"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-89157"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89157"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-89157"
        }
      ],
      "published": "2026-09-11T04:18:03+00:00",
      "updated": "2026-09-16T19:25:08+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-89158",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-89158"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-89158"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-fmgr-6ggq-9859"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89158"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-89158"
        }
      ],
      "published": "2026-09-11T04:18:03+00:00",
      "updated": "2026-09-16T19:23:41+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-89160",
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "low"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        125
      ],
      "description": "PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-89160"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-89160"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-9qww-pwc4-77qq"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89160"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-89160"
        }
      ],
      "published": "2026-09-11T04:18:04+00:00",
      "updated": "2026-09-16T19:15:29+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-89161",
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 7.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        590
      ],
      "description": "In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-89161"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-89161"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/commit/1dcd0cf42a6a7cb62cc9a7c024196733abcfda95%20%28pcre2-10.48-RC1%29"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/pull/937"
        },
        {
          "url": "https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89161"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-89161"
        }
      ],
      "published": "2026-09-11T04:18:04+00:00",
      "updated": "2026-09-16T19:10:47+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "10.40-6.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-8924",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        201
      ],
      "description": "A flaw in curl\u2019s cookie parsing logic allows a malicious HTTP server to set\n\"super cookies\" that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8924"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69125"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8924"
        },
        {
          "url": "https://bugzilla.redhat.com/2496759"
        },
        {
          "url": "https://bugzilla.redhat.com/2496760"
        },
        {
          "url": "https://bugzilla.redhat.com/2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/2496765"
        },
        {
          "url": "https://bugzilla.redhat.com/2496767"
        },
        {
          "url": "https://bugzilla.redhat.com/2496771"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496759"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496760"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496765"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496767"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496771"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8924.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8924.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8924.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-11856"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8458"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8924"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8926"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8932"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9079"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-69125.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69125"
        },
        {
          "url": "https://github.com/advisories/GHSA-hm6c-rc5h-32m9"
        },
        {
          "url": "https://hackerone.com/reports/3733905"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-8924.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-69125.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8924"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8924"
        }
      ],
      "published": "2026-07-03T07:16:24+00:00",
      "updated": "2026-09-15T07:16:32+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-8927",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 9.1,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        294
      ],
      "description": "When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`.",
      "recommendation": "Upgrade curl-minimal to version 7.76.1-40.el9_8.7; Upgrade libcurl-minimal to version 7.76.1-40.el9_8.7",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8927"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69126"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8927"
        },
        {
          "url": "https://bugzilla.redhat.com/2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/2496769"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496769"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8927.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8927.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8927.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8458"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8927"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-69126.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69126"
        },
        {
          "url": "https://github.com/advisories/GHSA-jr4f-4564-w3mr"
        },
        {
          "url": "https://hackerone.com/reports/3744543"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-8927.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-69126.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8927"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8487-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8820-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8927"
        }
      ],
      "published": "2026-07-03T07:16:25+00:00",
      "updated": "2026-09-15T07:16:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-8932",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "julia"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "low"
        }
      ],
      "cwes": [
        305
      ],
      "description": "libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-8932"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69125"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-8932"
        },
        {
          "url": "https://bugzilla.redhat.com/2496759"
        },
        {
          "url": "https://bugzilla.redhat.com/2496760"
        },
        {
          "url": "https://bugzilla.redhat.com/2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/2496765"
        },
        {
          "url": "https://bugzilla.redhat.com/2496767"
        },
        {
          "url": "https://bugzilla.redhat.com/2496771"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496759"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496760"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496764"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496765"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496767"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496771"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://curl.se/L7HzKXisfJ/CVE-2026-8932.md"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8932.html"
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8932.json"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-11856"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8458"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8924"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8926"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8932"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9079"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-69125.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69125"
        },
        {
          "url": "https://github.com/advisories/GHSA-m7xm-hf59-w6rj"
        },
        {
          "url": "https://hackerone.com/reports/3733910"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-8932.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-69125.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8932"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8670-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8670-2"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8670-3"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-8932"
        }
      ],
      "published": "2026-07-03T07:16:25+00:00",
      "updated": "2026-09-15T07:16:33+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "7.76.1-40.el9_8.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. curl/libcurl is base-image tooling; CP application code never drives the vulnerable mTLS connection-reuse pattern."
      }
    },
    {
      "id": "CVE-2026-90781",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "cwes": [
        193
      ],
      "description": "alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite adjacent stack memory and crash the calling process.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-90781"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-90781"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/control/ctlparse.c#L216-L241"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/commit/f84cd4ced7b36fddb8e4ee24404cf7c091d27020"
        },
        {
          "url": "https://lore.kernel.org/alsa-devel/CACBQ=P2FhO3M6dkv3cWuKb6Qhs92ouV+FJ3SJZ_PVBSSdJWRAQ@mail.gmail.com/"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90781"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-90781"
        },
        {
          "url": "https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-off-by-one-stack-buffer-overflow-in-snd-ctl-ascii-elem-id-parse"
        }
      ],
      "published": "2026-09-13T13:16:29+00:00",
      "updated": "2026-09-24T20:47:31+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.2.15.3-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-9149",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "nvd"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        122
      ],
      "description": "A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS).",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-9149"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21333"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28236"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48818"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-9149"
        },
        {
          "url": "https://bugzilla.redhat.com/2460379"
        },
        {
          "url": "https://bugzilla.redhat.com/2460380"
        },
        {
          "url": "https://bugzilla.redhat.com/2460425"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460425"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-48864"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9149"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9150"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-28236.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28236"
        },
        {
          "url": "https://github.com/openSUSE/libsolv/pull/617"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-9149.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-28236.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9149"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-9149"
        }
      ],
      "published": "2026-05-21T00:16:35+00:00",
      "updated": "2026-09-01T12:17:49+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.7.24-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-9150",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        121
      ],
      "description": "A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-9150"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:21333"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:28236"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30649"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48818"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-9150"
        },
        {
          "url": "https://bugzilla.redhat.com/2460379"
        },
        {
          "url": "https://bugzilla.redhat.com/2460380"
        },
        {
          "url": "https://bugzilla.redhat.com/2460425"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460379"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460380"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460425"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-48864"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9149"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9150"
        },
        {
          "url": "https://errata.almalinux.org/10/ALSA-2026-28236.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:28236"
        },
        {
          "url": "https://github.com/openSUSE/libsolv/pull/616"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-9150.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-28236.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9150"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-9150"
        }
      ],
      "published": "2026-05-20T23:16:36+00:00",
      "updated": "2026-09-01T12:17:50+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "0.7.24-6.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. The affected component is an operating-system base-image package that the product's application code does not use, so the vulnerable code path is not reachable."
      }
    },
    {
      "id": "CVE-2026-93541",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-93541"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-93541"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=7b6fffd13fd3914e0b39f3a4f131913da7f066e7"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93541"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-93541"
        }
      ],
      "published": "2026-09-24T16:17:26+00:00",
      "updated": "2026-09-24T21:00:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.7.10-8.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-93542",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() in libXi before 1.8.4 could be used by malicous servers to crash the X client.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-93542"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-93542"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=f499944ad595b9bd7e7571c810842244caf150aa"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93542"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-93542"
        }
      ],
      "published": "2026-09-24T17:17:10+00:00",
      "updated": "2026-09-24T21:00:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.7.10-8.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-93543",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-93543"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-93543"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=e2089ab748828273f916bbffd4e65b506aa50fdc"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93543"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-93543"
        }
      ],
      "published": "2026-09-24T17:17:10+00:00",
      "updated": "2026-09-24T21:00:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.7.10-8.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-93544",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-93544"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-93544"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=a88a341135b79f6ed450f481e4a5d6ba502382af"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93544"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-93544"
        }
      ],
      "published": "2026-09-24T17:17:10+00:00",
      "updated": "2026-09-24T21:00:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.7.10-8.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-93545",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-93545"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-93545"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=234ce17d95c42d75f7f7fdb2bf7a24875451bc0a"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93545"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-93545"
        }
      ],
      "published": "2026-09-24T17:17:10+00:00",
      "updated": "2026-09-24T21:00:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.7.10-8.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-93990",
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        176
      ],
      "description": "Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds.",
      "recommendation": "Upgrade expat to version 2.5.0-6.el9_8.5",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-93990"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:72663"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-93990"
        },
        {
          "url": "https://blog.hartwork.org/posts/expat-2-8-5-released/"
        },
        {
          "url": "https://bugzilla.redhat.com/2538967"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517901"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2538967"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-66046"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-93990"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-72663.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:72663"
        },
        {
          "url": "https://github.com/libexpat/libexpat"
        },
        {
          "url": "https://github.com/libexpat/libexpat/commit/ff6e1d7e750bbe245178f51a47a965dc8342861a"
        },
        {
          "url": "https://github.com/libexpat/libexpat/pull/1282"
        },
        {
          "url": "https://github.com/libexpat/libexpat/releases/tag/R_2_8_5"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-93990.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-74001.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93990"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-93990"
        },
        {
          "url": "https://www.vulncheck.com/advisories/expat-through-2.8.4-malformed-utf-16-acceptance-via-unchecked-surrogate"
        }
      ],
      "published": "2026-09-19T23:17:10+00:00",
      "updated": "2026-09-28T17:17:53+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.5.0-6.el9_8.3",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/expat@2.5.0-6.el9_8.3?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "Exploitability analysis, additional details:\nTemurin JVM binary is linked only against glibc:\n$ ldd /usr/lib/jvm/temurin-17-jre/bin/java\n        linux-vdso.so.1 (0x0000ffff8cd00000)\n        libjli.so => /usr/lib/jvm/temurin-17-jre/bin/../lib/libjli.so (0x0000ffff8cc70000)\n        libpthread.so.0 => /lib64/libpthread.so.0 (0x0000ffff8cc3b000)\n        libdl.so.2 => /lib64/libdl.so.2 (0x0000ffff8cc1a000)\n        libc.so.6 => /lib64/libc.so.6 (0x0000ffff8caa4000)\n        /lib/ld-linux-aarch64.so.1 (0x0000ffff8ccc2000)"
      }
    },
    {
      "id": "CVE-2026-94281",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-94281"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-94281"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23/diffs?commit_id=605f419d013153bf9e026cd100752ffbe930f3c1"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94281"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-94281"
        }
      ],
      "published": "2026-09-24T17:17:16+00:00",
      "updated": "2026-09-24T21:00:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.7.10-8.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libXi@1.7.10-8.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-94283",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-94283"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-94283"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=42d0303f243002a9856c76060569a61893c670dd"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94283"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-94283"
        }
      ],
      "published": "2026-09-28T09:17:08+00:00",
      "updated": "2026-09-30T13:17:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.8.12-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.8.12-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-94284",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-94284"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-94284"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=1b7904002d212eed40949ccf4e8e7156f9fec0e2"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94284"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-94284"
        }
      ],
      "published": "2026-09-28T09:17:08+00:00",
      "updated": "2026-09-30T13:17:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.8.12-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.8.12-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-94285",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "cwes": [
        125
      ],
      "description": "An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-94285"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-94285"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=980868483446f24f9658d26aa5bfa42f3da6dd3a"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94285"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-94285"
        }
      ],
      "published": "2026-09-28T09:17:08+00:00",
      "updated": "2026-09-30T13:17:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.8.12-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.8.12-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libX11-common@1.8.12-1.el9?arch=noarch&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libX11@1.8.12-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-94286",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        }
      ],
      "cwes": [
        126
      ],
      "description": "An out-of-bounds read in libXtst's RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to crash attached X clients.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-94286"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-94286"
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxtst/-/merge_requests/10/diffs?commit_id=16023c86070e6af9407330deea3938fcef75815b"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94286"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-94286"
        }
      ],
      "published": "2026-09-28T09:17:08+00:00",
      "updated": "2026-09-30T13:17:26+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libXtst@1.2.3-16.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.2.3-16.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libXtst@1.2.3-16.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libXtst@1.2.3-16.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libXtst@1.2.3-16.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libXtst@1.2.3-16.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libXtst@1.2.3-16.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libXtst@1.2.3-16.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libXtst@1.2.3-16.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libXtst@1.2.3-16.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libXtst@1.2.3-16.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libXtst@1.2.3-16.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libXtst@1.2.3-16.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libXtst@1.2.3-16.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libXtst@1.2.3-16.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libXtst@1.2.3-16.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-95512",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        400
      ],
      "description": "A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-95512"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:74952"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-95512"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2462295"
        },
        {
          "url": "https://gitlab.freedesktop.org/freetype/freetype/-/commit/f3ca71c9900fe860849b3163a6e2c1e765b291d9"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-95512"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8881-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-95512"
        }
      ],
      "published": "2026-10-02T09:16:45+00:00",
      "updated": "2026-10-06T03:17:09+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.10.4-10.el9_5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/freetype@2.10.4-10.el9_5?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-95519",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        78
      ],
      "description": "A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because manifest entries are unexpectedly macro-expanded before being opened, allowing embedded shell commands to run with the privileges of the `rpm` process. Successful exploitation can lead to a full compromise of confidentiality, integrity, and availability for the affected account.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-95519"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-95519"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2470977"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-95519"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-95519"
        }
      ],
      "published": "2026-09-24T14:18:20+00:00",
      "updated": "2026-09-25T13:17:23+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-95520",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
        }
      ],
      "cwes": [
        787
      ],
      "description": "A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared RPMTAG_LONGFILESIZES value is 0xFFFFFFFFFFFFFFFF causes an integer overflow in iterReadArchiveNext() that shrinks a buffer allocation to one byte, after which the payload's independently-controlled cpio filesize field is used to write attacker-controlled data past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an  untrusted package.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-95520"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-95520"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2537809"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-95520"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-95520"
        }
      ],
      "published": "2026-09-29T12:17:12+00:00",
      "updated": "2026-09-29T21:29:07+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-95521",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.8,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        78
      ],
      "description": "A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating the source file list. This allows arbitrary command execution as the invoking (typically non-root) user, simply by installing, rebuilding, or otherwise processing an untrusted .src.rpm.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-95521"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-95521"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2537812"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-95521"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-95521"
        }
      ],
      "published": "2026-09-24T14:18:20+00:00",
      "updated": "2026-09-24T21:00:46+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "4.16.1.3-40.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/python3-rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-build-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-plugin-systemd-inhibit@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm-sign-libs@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-95619",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "medium"
        }
      ],
      "cwes": [
        190
      ],
      "description": "A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-95619"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:58503"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67275"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-95619"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2537811"
        },
        {
          "url": "https://gcc.gnu.org/pipermail/gcc-patches/2026-September/732381.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-95619"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-95619"
        }
      ],
      "published": "2026-09-22T13:17:13+00:00",
      "updated": "2026-09-22T19:37:36+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "11.5.0-14.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libgomp@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-95818",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        121
      ],
      "description": "A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-95818"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-95818"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-95818"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34360"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-95818"
        }
      ],
      "published": "2026-09-22T17:17:32+00:00",
      "updated": "2026-09-22T19:56:19+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-96674",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 4.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
        }
      ],
      "cwes": [
        190
      ],
      "description": "alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowing integer overflow that defeats bounds checks. Attackers can supply crafted topology files that wrap size calculations, causing the decoder to read beyond the topology buffer and potentially leak sensitive data or crash the application.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-96674"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-96674"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1316-L1326"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1420-L1430"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1511-L1521"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/pull/527"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-96674"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-96674"
        },
        {
          "url": "https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-integer-overflow-via-topology-file"
        }
      ],
      "published": "2026-09-23T16:16:50+00:00",
      "updated": "2026-09-24T21:08:55+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.2.15.3-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-96675",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        129
      ],
      "description": "alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate sparse binding indices before array access. Attackers can supply a malicious ALSA configuration file with sparse bindings to trigger an out-of-bounds array read and assertion failure, causing the application to abort.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-96675"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-96675"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/pcm/pcm_multi.c#L1122-L1131"
        },
        {
          "url": "https://github.com/alsa-project/alsa-lib/pull/527"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-96675"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-96675"
        },
        {
          "url": "https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-denial-of-service-via-pcm-multi"
        }
      ],
      "published": "2026-09-23T16:16:50+00:00",
      "updated": "2026-09-24T21:08:55+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "1.2.15.3-1.el9",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/alsa-lib@1.2.15.3-1.el9?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-97399",
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 3.7,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        126
      ],
      "description": "The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable.",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-97399"
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/09/28/7"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-97399"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-97399"
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34683"
        },
        {
          "url": "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-97399"
        }
      ],
      "published": "2026-09-28T16:17:18+00:00",
      "updated": "2026-09-29T21:36:39+00:00",
      "affects": [
        {
          "ref": "pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8",
          "versions": [
            {
              "version": "2.34-275.el9_8",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        },
        {
          "ref": "urn:cdx:f6c59eff-aacc-47fe-b2d1-891a608eedc7/1#pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=redhat-9.8"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-97687",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.4,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        295,
        440
      ],
      "description": "urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cert_reqs, verify_mode, use_forwarding_for_https=True, and CERT_NONE configuration paths fail to remain separated because target-server TLS settings are incorrectly applied to the HTTPS proxy connection. The trigger is that an application uses an HTTPS proxy and configures target-server TLS settings that must remain separate from the proxy TLS handshake, including HTTPS forwarding with target-specific identity or credentials. Applying cert_reqs=CERT_NONE can overwrite proxy_ssl_context.verify_mode in place, and the mutation persists so later connections reusing the same context may connect to the HTTPS proxy without certificate verification. The attack mechanism is that an attacker intercepts and impersonates the HTTPS proxy after the effective proxy policy accepts the attacker's certificate. The impact is that the attacker can observe or modify forwarded traffic or receive a target TLS client certificate, while CONNECT tunneling still preserves the separate end-to-end target TLS connection. This issue is fixed in version 2.8.0.",
      "recommendation": "Upgrade urllib3 to version 2.8.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-97687"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-97687"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-97687"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/07408cec79d1856d81bb42c74a904a24fdb9e465"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/b6447295fff7b38fdffc67e0df9712d60cef3cc3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/pull/5093"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/2.8.0"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-97687"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-97687"
        }
      ],
      "published": "2026-09-29T16:17:18+00:00",
      "updated": "2026-09-30T21:17:19+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@2.7.0",
          "versions": [
            {
              "version": "2.7.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:pypi/urllib3@2.7.0",
          "versions": [
            {
              "version": "2.7.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:pypi/urllib3@2.7.0"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-97688",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        835
      ],
      "description": "urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains trailing bytes as unconsumed input after reaching end-of-stream and repeatedly decodes them without progress. The issue occurs when an untrusted server sends a chunked Deflate response whose decoded body exceeds a positive finite chunk size and whose encoded body has trailing bytes, specifically a response with Transfer-Encoding: chunked and Content-Encoding: deflate, content decoding enabled, and the positive finite amt=N streaming chunk size. The attack mechanism is that a malicious server returns a compressed chunked response with trailing bytes after the Deflate stream. The impact is excessive CPU usage and a request that does not complete, and network read timeouts do not interrupt the loop because no further socket read occurs. This issue is fixed in version 2.8.0.",
      "recommendation": "Upgrade urllib3 to version 2.8.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-97688"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-97688"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-97688"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/2.8.0"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-97688"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-97688"
        }
      ],
      "published": "2026-09-29T16:17:18+00:00",
      "updated": "2026-09-30T19:38:27+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@2.7.0",
          "versions": [
            {
              "version": "2.7.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:pypi/urllib3@2.7.0",
          "versions": [
            {
              "version": "2.7.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:pypi/urllib3@2.7.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-97689",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        770
      ],
      "description": "urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field until newline or EOF without a length bound. The trigger is that a malicious server returns Transfer-Encoding: chunked followed by a very long run of bytes without a newline. The attack mechanism is that a malicious HTTP server sends a very long unterminated chunk-size line. The impact is that unbounded memory allocation can exhaust the client process. This issue is fixed in version 2.8.0.",
      "recommendation": "Upgrade urllib3 to version 2.8.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-97689"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-97689"
        },
        {
          "url": "https://advisory.echohq.com/cve/CVE-2026-97689"
        },
        {
          "url": "https://github.com/urllib3/urllib3"
        },
        {
          "url": "https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed"
        },
        {
          "url": "https://github.com/urllib3/urllib3/releases/tag/2.8.0"
        },
        {
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-97689"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-97689"
        }
      ],
      "published": "2026-09-29T16:17:18+00:00",
      "updated": "2026-09-30T19:38:27+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@2.7.0",
          "versions": [
            {
              "version": "2.7.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:pypi/urllib3@2.7.0",
          "versions": [
            {
              "version": "2.7.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:pypi/urllib3@2.7.0"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "GHSA-6v7p-g79w-8964",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip"
      },
      "ratings": [
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "description": "### Impact\n\nIf the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV.\n\nIf the Unpacker is used repeatedly to unpack untrusted input from external sources, it may be vulnerable to a DoS attack.\n\n### Patches\n\nv1.2.1\n\n### Workarounds\n\nUsers should create a new Unpacker instead of reusing the same Unpacker after an error occurs.\n\nApplying the above patch can prevent SEGV, but reusing the Streaming Unpacker after it has encountered an error will not yield correct data. If an error occurs during Streaming Unpacking, the Stream and Streaming Unpacker should be discarded.\n\nTherefore, this is not just a workaround but the correct solution. The above patch only prevents crashes from incorrect usage.",
      "recommendation": "Upgrade msgpack to version 1.2.1",
      "advisories": [
        {
          "url": "https://github.com/advisories/GHSA-6v7p-g79w-8964"
        },
        {
          "url": "https://advisory.echohq.com/cve/GHSA-6v7p-g79w-8964"
        },
        {
          "url": "https://github.com/msgpack/msgpack-python"
        },
        {
          "url": "https://github.com/msgpack/msgpack-python/commit/2c56ddb5d0025ed481d962c0f5d62d19dec7476d"
        },
        {
          "url": "https://github.com/msgpack/msgpack-python/releases/tag/v1.2.1"
        },
        {
          "url": "https://github.com/msgpack/msgpack-python/security/advisories/GHSA-6v7p-g79w-8964"
        }
      ],
      "published": "2026-06-19T21:42:55+00:00",
      "updated": "2026-06-19T21:42:55+00:00",
      "affects": [
        {
          "ref": "pkg:pypi/msgpack@1.1.2",
          "versions": [
            {
              "version": "1.1.2",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6ee0f936-cde6-4c69-b072-430fb771c2da/1#pkg:pypi/msgpack@1.1.2"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "code_not_reachable",
        "response": [
          "update"
        ],
        "detail": "This issue is not exploitable in the Confluent Platform. This issue will be addressed in an upcoming quarterly patch release if an updated package is available from the vendor. No CP source repo declares msgpack directly; the most plausible bundling path (pip's vendored copy) is exercised only at image-build time, not at product runtime."
      }
    },
    {
      "id": "CVE-2026-39824",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "cwes": [
        190
      ],
      "description": "NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error.",
      "recommendation": "Upgrade golang.org/x/sys to version 0.44.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39824"
        },
        {
          "url": "https://go.dev/cl/770080"
        },
        {
          "url": "https://go.dev/issue/78916"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/6MMI8Lj-Atg"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5024"
        }
      ],
      "published": "2026-05-22T20:16:33+00:00",
      "updated": "2026-07-23T16:10:00+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/sys@v0.7.0",
          "versions": [
            {
              "version": "v0.7.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:golang/golang.org/x/sys@v0.7.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56857",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target).",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56857"
        },
        {
          "url": "https://go.dev/cl/847305"
        },
        {
          "url": "https://go.dev/issue/81739"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6604"
        }
      ],
      "published": "2026-10-08T23:17:01+00:00",
      "updated": "2026-10-08T23:17:01+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.27.1",
          "versions": [
            {
              "version": "v1.27.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56866",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56866"
        },
        {
          "url": "https://go.dev/cl/847306"
        },
        {
          "url": "https://go.dev/issue/81740"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6605"
        }
      ],
      "published": "2026-10-08T23:17:01+00:00",
      "updated": "2026-10-08T23:17:01+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.27.1",
          "versions": [
            {
              "version": "v1.27.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-78659",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-78659"
        },
        {
          "url": "https://go.dev/cl/847185"
        },
        {
          "url": "https://go.dev/cl/847314"
        },
        {
          "url": "https://go.dev/issue/81857"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6603"
        }
      ],
      "published": "2026-10-08T23:17:03+00:00",
      "updated": "2026-10-08T23:17:03+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.27.1",
          "versions": [
            {
              "version": "v1.27.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.56.0",
          "versions": [
            {
              "version": "v0.56.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/golang.org/x/net@v0.56.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-78660",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-78660"
        },
        {
          "url": "https://go.dev/cl/835145"
        },
        {
          "url": "https://go.dev/cl/836385"
        },
        {
          "url": "https://go.dev/issue/81115"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6610"
        }
      ],
      "published": "2026-10-08T23:17:03+00:00",
      "updated": "2026-10-08T23:17:03+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.27.1",
          "versions": [
            {
              "version": "v1.27.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.56.0",
          "versions": [
            {
              "version": "v0.56.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/golang.org/x/net@v0.56.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-78663",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-78663"
        },
        {
          "url": "https://go.dev/cl/847187"
        },
        {
          "url": "https://go.dev/cl/847310"
        },
        {
          "url": "https://go.dev/issue/81743"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6612"
        }
      ],
      "published": "2026-10-08T23:17:03+00:00",
      "updated": "2026-10-08T23:17:03+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.27.1",
          "versions": [
            {
              "version": "v1.27.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.56.0",
          "versions": [
            {
              "version": "v0.56.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/golang.org/x/net@v0.56.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-78667",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "description": "When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-78667"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-78667"
        },
        {
          "url": "https://go.dev/cl/847309"
        },
        {
          "url": "https://go.dev/issue/81858"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78667"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6609"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-78667"
        }
      ],
      "published": "2026-10-08T23:17:03+00:00",
      "updated": "2026-10-08T23:17:03+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.27.1",
          "versions": [
            {
              "version": "v1.27.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-78669",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-78669"
        },
        {
          "url": "https://go.dev/cl/847186"
        },
        {
          "url": "https://go.dev/cl/847308"
        },
        {
          "url": "https://go.dev/issue/81742"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6611"
        }
      ],
      "published": "2026-10-08T23:17:04+00:00",
      "updated": "2026-10-08T23:17:04+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.27.1",
          "versions": [
            {
              "version": "v1.27.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.56.0",
          "versions": [
            {
              "version": "v0.56.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/golang.org/x/net@v0.56.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-94439",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.5,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "description": "When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP. The impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-94439"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-94439"
        },
        {
          "url": "https://go.dev/cl/847311"
        },
        {
          "url": "https://go.dev/issue/81744"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94439"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6613"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-94439"
        }
      ],
      "published": "2026-10-08T23:17:04+00:00",
      "updated": "2026-10-08T23:17:04+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.27.1",
          "versions": [
            {
              "version": "v1.27.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-94440",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-94440"
        },
        {
          "url": "https://go.dev/cl/847307"
        },
        {
          "url": "https://go.dev/issue/81741"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6608"
        }
      ],
      "published": "2026-10-08T23:17:04+00:00",
      "updated": "2026-10-08T23:17:04+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.27.1",
          "versions": [
            {
              "version": "v1.27.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-94448",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression. We now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-94448"
        },
        {
          "url": "https://go.dev/cl/839866"
        },
        {
          "url": "https://go.dev/issue/81821"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6599"
        }
      ],
      "published": "2026-10-08T23:17:05+00:00",
      "updated": "2026-10-08T23:17:05+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.27.1",
          "versions": [
            {
              "version": "v1.27.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-97030",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-97030"
        },
        {
          "url": "https://go.dev/cl/840925"
        },
        {
          "url": "https://go.dev/issue/81823"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6600"
        }
      ],
      "published": "2026-10-08T23:17:05+00:00",
      "updated": "2026-10-08T23:17:05+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.27.1",
          "versions": [
            {
              "version": "v1.27.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-97031",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "description": "Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-97031"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-97031"
        },
        {
          "url": "https://go.dev/cl/847312"
        },
        {
          "url": "https://go.dev/issue/81855"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-97031"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6607"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-97031"
        }
      ],
      "published": "2026-10-08T23:17:06+00:00",
      "updated": "2026-10-08T23:17:06+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.27.1",
          "versions": [
            {
              "version": "v1.27.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-97032",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "description": "HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server.",
      "recommendation": "Upgrade stdlib to version 1.26.9, 1.27.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-97032"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-97032"
        },
        {
          "url": "https://go.dev/cl/847188"
        },
        {
          "url": "https://go.dev/cl/847313"
        },
        {
          "url": "https://go.dev/issue/81867"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-97032"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6617"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-97032"
        }
      ],
      "published": "2026-10-08T23:17:06+00:00",
      "updated": "2026-10-08T23:17:06+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.27.1",
          "versions": [
            {
              "version": "v1.27.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/net@v0.56.0",
          "versions": [
            {
              "version": "v0.56.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:6b9d9b79-3521-49ba-95b4-a37f14bfced5/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:74532f66-a815-40f3-8f09-5797d3f6f694/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:4a43fcf5-ce3d-4ca7-9155-3537325fdf0c/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:b54ca283-284d-4e07-ba51-ff9509e257a0/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:1031fcf8-a1ef-4dc7-9add-98bc4f0e3fac/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:e55775d6-a1a3-4829-8f7c-c1c1f614911d/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:30e57ca0-c929-4550-b8b0-d3b6e12dfa39/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:59a74648-25ff-495f-9911-b9df0ddf2cf3/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:7bb07979-396d-43ed-981d-ee82deea2ee3/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:07515ccb-1304-4261-8d8b-2443137de873/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:00759b8a-0151-49bb-bc1b-522c9adcad89/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:849cc4ca-c5b6-4dbc-8a74-1028610bc7d9/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:bcd0c2f2-00b2-4a36-9f8d-ed46479d9552/1#pkg:golang/stdlib@v1.27.1"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/stdlib@v1.26.5"
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/golang.org/x/net@v0.56.0"
        }
      ],
      "analysis": {
        "state": "not_affected",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-33818",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        400
      ],
      "description": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-33818"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70641"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-33818"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402034"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11395"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-70641.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:70641"
        },
        {
          "url": "https://go.dev/cl/814980"
        },
        {
          "url": "https://go.dev/issue/80405"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-33818.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33818"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5972"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33818"
        }
      ],
      "published": "2026-08-13T22:17:19+00:00",
      "updated": "2026-09-03T16:37:52+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-39821",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.2,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ubuntu"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        1289
      ],
      "description": "The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-39821"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:23264"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26546"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26547"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30650"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30853"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30854"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:30855"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33155"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33163"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33173"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33183"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33524"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:33531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34342"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34357"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34359"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34364"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34789"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35826"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35827"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35828"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35829"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35830"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35831"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35993"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:35994"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36105"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36167"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36207"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36648"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36651"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36797"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36808"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36820"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36883"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:37436"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38995"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39005"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39573"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39879"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40118"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40262"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40945"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41019"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41030"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41031"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41036"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41055"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41066"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41928"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41930"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42043"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42047"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42048"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42049"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42050"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42051"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42078"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42079"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42080"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42082"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42132"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42142"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42146"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42150"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42151"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42240"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42644"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42796"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42852"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43038"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43052"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43692"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44622"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:44624"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47149"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47735"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47737"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47952"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49702"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49712"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50300"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:50843"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51033"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51112"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51187"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:51341"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:52826"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53374"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53412"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53413"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53415"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:53530"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54191"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54274"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54283"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54284"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54285"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54286"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54287"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54395"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54401"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54435"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54441"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54531"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54580"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:54757"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56143"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56223"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56340"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:56431"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57194"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57541"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57649"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:57845"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59546"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59549"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:59562"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60315"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60354"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60387"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:60520"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61245"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:61253"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:62549"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:63134"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65126"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65153"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65359"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65534"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65851"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:65886"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66016"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66022"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66350"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:66432"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67149"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67159"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67160"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67287"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67319"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:67517"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:68504"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-39821"
        },
        {
          "url": "https://bugzilla.redhat.com/2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/2467820"
        },
        {
          "url": "https://bugzilla.redhat.com/2480756"
        },
        {
          "url": "https://bugzilla.redhat.com/2484204"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/2515840"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456333"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2456339"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467809"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467822"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480756"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484204"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515840"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-65153.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:65886"
        },
        {
          "url": "https://go.dev/cl/767220"
        },
        {
          "url": "https://go.dev/issue/78760"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-39821.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-66432-0.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5026"
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8416-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8883-1"
        },
        {
          "url": "https://ubuntu.com/security/notices/USN-8900-1"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-39821"
        }
      ],
      "published": "2026-05-22T16:16:20+00:00",
      "updated": "2026-09-17T12:18:05+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-46600",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        125
      ],
      "description": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.",
      "recommendation": "Upgrade stdlib to version 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-46600"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-46600"
        },
        {
          "url": "https://go.dev/cl/786345"
        },
        {
          "url": "https://go.dev/issue/79795"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46600"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5942"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-46600"
        }
      ],
      "published": "2026-07-21T20:17:01+00:00",
      "updated": "2026-08-14T16:16:55+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "in_triage",
        "justification": "",
        "response": [],
        "detail": "This CVE is under investigation by Confluent."
      }
    },
    {
      "id": "CVE-2026-56851",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "cwes": [
        787
      ],
      "description": "The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer.",
      "recommendation": "Upgrade golang.org/x/text to version 0.41.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56851"
        },
        {
          "url": "https://go.dev/cl/793360"
        },
        {
          "url": "https://go.dev/issue/80112"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6629"
        }
      ],
      "published": "2026-10-07T18:17:20+00:00",
      "updated": "2026-10-08T21:35:53+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/text@v0.40.0",
          "versions": [
            {
              "version": "v0.40.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/text@v0.40.0",
          "versions": [
            {
              "version": "v0.40.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/text@v0.40.0",
          "versions": [
            {
              "version": "v0.40.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/text@v0.40.0",
          "versions": [
            {
              "version": "v0.40.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/text@v0.40.0",
          "versions": [
            {
              "version": "v0.40.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/text@v0.40.0",
          "versions": [
            {
              "version": "v0.40.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/golang.org/x/text@v0.40.0"
        }
      ]
    },
    {
      "id": "CVE-2026-56853",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        770
      ],
      "description": "When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56853"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70641"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56853"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402034"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11395"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-70641.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:70641"
        },
        {
          "url": "https://go.dev/cl/795540"
        },
        {
          "url": "https://go.dev/issue/80205"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-56853.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56853"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6089"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56853"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-09-03T16:37:52+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56854",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.8,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "cwes": [
        863
      ],
      "description": "The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.55.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56854"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56854"
        },
        {
          "url": "https://go.dev/cl/797040"
        },
        {
          "url": "https://go.dev/issue/80213"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56854"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6303"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56854"
        }
      ],
      "published": "2026-08-28T16:18:17+00:00",
      "updated": "2026-09-03T16:37:52+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.54.0",
          "versions": [
            {
              "version": "v0.54.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.54.0",
          "versions": [
            {
              "version": "v0.54.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.54.0",
          "versions": [
            {
              "version": "v0.54.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.54.0",
          "versions": [
            {
              "version": "v0.54.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.54.0",
          "versions": [
            {
              "version": "v0.54.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.54.0",
          "versions": [
            {
              "version": "v0.54.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/golang.org/x/crypto@v0.54.0"
        }
      ]
    },
    {
      "id": "CVE-2026-56855",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.56.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56855"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70640"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56855"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402034"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503742"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2528050"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11395"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-15789"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56855"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-70640.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:70640"
        },
        {
          "url": "https://go.dev/cl/826524"
        },
        {
          "url": "https://go.dev/issue/81317"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/1y3fb2np35U"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-56855.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70640.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56855"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6355"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56855"
        }
      ],
      "published": "2026-09-02T20:17:36+00:00",
      "updated": "2026-09-04T16:34:56+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.54.0",
          "versions": [
            {
              "version": "v0.54.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.54.0",
          "versions": [
            {
              "version": "v0.54.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.54.0",
          "versions": [
            {
              "version": "v0.54.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.54.0",
          "versions": [
            {
              "version": "v0.54.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.54.0",
          "versions": [
            {
              "version": "v0.54.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.54.0",
          "versions": [
            {
              "version": "v0.54.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/golang.org/x/crypto@v0.54.0"
        }
      ]
    },
    {
      "id": "CVE-2026-56858",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 6.1,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "critical"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        79
      ],
      "description": "Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56858"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70641"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56858"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402034"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11395"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-70641.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:70641"
        },
        {
          "url": "https://go.dev/cl/807100"
        },
        {
          "url": "https://go.dev/issue/80435"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-56858.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56858"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6091"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56858"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-09-03T16:37:52+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56859",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56859"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:69961"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56859"
        },
        {
          "url": "https://bugzilla.redhat.com/2480684"
        },
        {
          "url": "https://bugzilla.redhat.com/2508234"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/2515840"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480684"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2508234"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515840"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2518147"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-17106"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19730"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39830"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-69961.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:69961"
        },
        {
          "url": "https://go.dev/cl/803320"
        },
        {
          "url": "https://go.dev/issue/80481"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-56859.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70201.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56859"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6088"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56859"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-09-03T16:37:52+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56860",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 5.9,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        407
      ],
      "description": "Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56860"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70641"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56860"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402034"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11395"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-70641.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:70641"
        },
        {
          "url": "https://go.dev/cl/803681"
        },
        {
          "url": "https://go.dev/issue/80494"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-56860.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56860"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6218"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56860"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-09-03T16:37:52+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-56862",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "alma"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "bitnami"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "oracle-oval"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "photon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.",
      "recommendation": "Upgrade stdlib to version 1.25.13, 1.26.6, 1.27.0-rc.3",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-56862"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:70641"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-56862"
        },
        {
          "url": "https://bugzilla.redhat.com/2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/2515839"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2402034"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515815"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515820"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515827"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515838"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515839"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-11395"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862"
        },
        {
          "url": "https://errata.almalinux.org/9/ALSA-2026-70641.html"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:70641"
        },
        {
          "url": "https://go.dev/cl/804261"
        },
        {
          "url": "https://go.dev/issue/80528"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "url": "https://linux.oracle.com/cve/CVE-2026-56862.html"
        },
        {
          "url": "https://linux.oracle.com/errata/ELSA-2026-70641.html"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56862"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6090"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-56862"
        }
      ],
      "published": "2026-08-13T22:17:22+00:00",
      "updated": "2026-09-03T16:37:52+00:00",
      "affects": [
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/stdlib@v1.26.5",
          "versions": [
            {
              "version": "v1.26.5",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/stdlib@v1.26.5"
        }
      ],
      "analysis": {
        "state": "resolved",
        "justification": "",
        "response": [
          "update"
        ],
        "detail": null
      }
    },
    {
      "id": "CVE-2026-71556",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L"
        }
      ],
      "cwes": [
        59
      ],
      "description": "go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a maliciously crafted repository containing a symlink can cause go-git to read from or write to files outside the intended working directory when the repository is cloned and its worktree operations are used. Versions 5.19.2 and 6.0.0-alpha.5.",
      "recommendation": "Upgrade github.com/go-git/go-git/v5 to version 5.19.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-71556"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-71556"
        },
        {
          "url": "https://github.com/go-git/go-git"
        },
        {
          "url": "https://github.com/go-git/go-git/commit/008a78f2dd86f52544ddff8b8e8ddeecdf3f7aab"
        },
        {
          "url": "https://github.com/go-git/go-git/commit/661d1c7f101d34e002a3cfcf8dbea5b7421d07ac"
        },
        {
          "url": "https://github.com/go-git/go-git/releases/tag/v5.19.2"
        },
        {
          "url": "https://github.com/go-git/go-git/releases/tag/v6.0.0-alpha.5"
        },
        {
          "url": "https://github.com/go-git/go-git/security/advisories/GHSA-hc8v-wwc9-vgxm"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71556"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-71556"
        }
      ],
      "published": "2026-08-07T17:17:10+00:00",
      "updated": "2026-09-10T20:41:33+00:00",
      "affects": [
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.19.1",
          "versions": [
            {
              "version": "v5.19.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.19.1",
          "versions": [
            {
              "version": "v5.19.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.19.1",
          "versions": [
            {
              "version": "v5.19.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.19.1",
          "versions": [
            {
              "version": "v5.19.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.19.1",
          "versions": [
            {
              "version": "v5.19.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.19.1",
          "versions": [
            {
              "version": "v5.19.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/github.com/go-git/go-git/v5@v5.19.1"
        }
      ]
    },
    {
      "id": "CVE-2026-71557",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "ghsa"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 6.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L"
        }
      ],
      "cwes": [
        22
      ],
      "description": "go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciously crafted reference name (for example containing directory-traversal sequences) can cause go-git to write files outside the intended reference storage directory. Versions 5.19.2 and 6.0.0-alpha.5 fix the issue.",
      "recommendation": "Upgrade github.com/go-git/go-git/v5 to version 5.19.2",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-71557"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-71557"
        },
        {
          "url": "https://github.com/go-git/go-git"
        },
        {
          "url": "https://github.com/go-git/go-git/commit/4a0e66d555de5f9a30c31e2df64f445f42bd01e7"
        },
        {
          "url": "https://github.com/go-git/go-git/commit/da9f7d8a0e98b475600177348d6ece384a370f36"
        },
        {
          "url": "https://github.com/go-git/go-git/pull/2247"
        },
        {
          "url": "https://github.com/go-git/go-git/pull/2254"
        },
        {
          "url": "https://github.com/go-git/go-git/releases/tag/v5.19.2"
        },
        {
          "url": "https://github.com/go-git/go-git/releases/tag/v6.0.0-alpha.5"
        },
        {
          "url": "https://github.com/go-git/go-git/security/advisories/GHSA-qgq7-7hm3-q39j"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71557"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-71557"
        }
      ],
      "published": "2026-08-07T17:17:10+00:00",
      "updated": "2026-09-10T20:41:33+00:00",
      "affects": [
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.19.1",
          "versions": [
            {
              "version": "v5.19.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.19.1",
          "versions": [
            {
              "version": "v5.19.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.19.1",
          "versions": [
            {
              "version": "v5.19.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.19.1",
          "versions": [
            {
              "version": "v5.19.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.19.1",
          "versions": [
            {
              "version": "v5.19.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/github.com/go-git/go-git/v5@v5.19.1",
          "versions": [
            {
              "version": "v5.19.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/github.com/go-git/go-git/v5@v5.19.1"
        }
      ]
    },
    {
      "id": "CVE-2026-78662",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [
        {
          "source": {
            "name": "amazon"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "azure"
          },
          "severity": "medium"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 5.3,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        770
      ],
      "description": "Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.",
      "recommendation": "Upgrade golang.org/x/crypto to version 0.56.0",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-78662"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-78662"
        },
        {
          "url": "https://go.dev/cl/826504"
        },
        {
          "url": "https://go.dev/issue/81316"
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/1y3fb2np35U"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78662"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-6354"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-78662"
        }
      ],
      "published": "2026-09-02T20:17:37+00:00",
      "updated": "2026-09-04T16:33:34+00:00",
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.54.0",
          "versions": [
            {
              "version": "v0.54.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.54.0",
          "versions": [
            {
              "version": "v0.54.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.54.0",
          "versions": [
            {
              "version": "v0.54.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.54.0",
          "versions": [
            {
              "version": "v0.54.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.54.0",
          "versions": [
            {
              "version": "v0.54.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.54.0",
          "versions": [
            {
              "version": "v0.54.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/golang.org/x/crypto@v0.54.0"
        }
      ]
    },
    {
      "id": "CVE-2026-84303",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [],
      "cwes": [
        178,
        863
      ],
      "description": "gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata keys are lowercase. A DENY policy using a mixed-case name such as X-Role or User-Agent therefore does not match and fails open, allowing requests that should be rejected. The same case mismatch permits :Scheme or Grpc-Status to evade gRFC A41 validation and prevents Host from being rewritten to :authority. This issue is fixed in version 1.83.1.",
      "recommendation": "Upgrade google.golang.org/grpc to version 1.83.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-84303"
        },
        {
          "url": "https://github.com/grpc/grpc-go"
        },
        {
          "url": "https://github.com/grpc/grpc-go/commit/db9482836c298f234c896cf82ab68cafc78237f8"
        },
        {
          "url": "https://github.com/grpc/grpc-go/commit/ebba6f3f1b206e2b4dc4d1d5a96d18430302c2fe"
        },
        {
          "url": "https://github.com/grpc/grpc-go/pull/9332"
        },
        {
          "url": "https://github.com/grpc/grpc-go/pull/9335"
        },
        {
          "url": "https://github.com/grpc/grpc-go/releases/tag/v1.83.1"
        },
        {
          "url": "https://github.com/grpc/grpc-go/security/advisories/GHSA-qc2q-p7wx-3px3"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84303"
        }
      ],
      "published": "2026-09-01T19:17:30+00:00",
      "updated": "2026-09-09T21:09:13+00:00",
      "affects": [
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.82.1",
          "versions": [
            {
              "version": "v1.82.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.82.1",
          "versions": [
            {
              "version": "v1.82.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.82.1",
          "versions": [
            {
              "version": "v1.82.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.82.1",
          "versions": [
            {
              "version": "v1.82.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.82.1",
          "versions": [
            {
              "version": "v1.82.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.82.1",
          "versions": [
            {
              "version": "v1.82.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/google.golang.org/grpc@v1.82.1"
        }
      ]
    },
    {
      "id": "CVE-2026-84304",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate heap memory even when payload bytes remain within connection and stream flow-control windows. An unauthenticated remote attacker can use concurrent multiplexed streams to exhaust process memory and cause a runtime panic or out-of-memory termination. Receive-buffer compaction is enabled by default and can be controlled temporarily with GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION. This issue is fixed in version 1.83.1.",
      "recommendation": "Upgrade google.golang.org/grpc to version 1.83.1",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-84304"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-84304"
        },
        {
          "url": "https://github.com/grpc/grpc-go"
        },
        {
          "url": "https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176"
        },
        {
          "url": "https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77"
        },
        {
          "url": "https://github.com/grpc/grpc-go/pull/9331"
        },
        {
          "url": "https://github.com/grpc/grpc-go/pull/9333"
        },
        {
          "url": "https://github.com/grpc/grpc-go/releases/tag/v1.83.1"
        },
        {
          "url": "https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84304"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-84304"
        }
      ],
      "published": "2026-09-01T19:17:30+00:00",
      "updated": "2026-09-09T21:09:13+00:00",
      "affects": [
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.82.1",
          "versions": [
            {
              "version": "v1.82.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.82.1",
          "versions": [
            {
              "version": "v1.82.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.82.1",
          "versions": [
            {
              "version": "v1.82.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.82.1",
          "versions": [
            {
              "version": "v1.82.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.82.1",
          "versions": [
            {
              "version": "v1.82.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.82.1",
          "versions": [
            {
              "version": "v1.82.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/google.golang.org/grpc@v1.82.1"
        }
      ]
    },
    {
      "id": "CVE-2026-84445",
      "source": {
        "name": "ghsa",
        "url": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago"
      },
      "ratings": [
        {
          "source": {
            "name": "azure"
          },
          "severity": "high"
        },
        {
          "source": {
            "name": "redhat"
          },
          "score": 7.5,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": {
            "name": "rocky"
          },
          "severity": "high"
        }
      ],
      "cwes": [
        129,
        248
      ],
      "description": "gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host header, while RouteAndProcess in internal/xds/server/routing.go assumes that an authority value exists and indexes the empty slice. A remote client that can complete transport connection establishment can trigger an index-out-of-bounds panic that is not recovered by the per-RPC goroutine and terminates the entire server process. In insecure or ordinary TLS deployments the request can be unauthenticated, while strict mTLS or ALTS deployments require valid transport credentials before the malformed RPC can reach the interceptor. This issue is fixed in versions 1.82.2 and 1.83.2.",
      "recommendation": "Upgrade google.golang.org/grpc to version 1.82.2, 1.83.2, 1.84.0-dev.0.20260825144003-d5a41119e0e3, 1.85.0-dev.0.20260825072537-93e31b48545e",
      "advisories": [
        {
          "url": "https://avd.aquasec.com/nvd/cve-2026-84445"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:76744"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-84445"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533175"
        },
        {
          "url": "https://creativecommons.org/licenses/by/4.0/"
        },
        {
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84445"
        },
        {
          "url": "https://errata.rockylinux.org/RLSA-2026:76744"
        },
        {
          "url": "https://github.com/grpc/grpc-go"
        },
        {
          "url": "https://github.com/grpc/grpc-go/commit/3822494d8ea03b992c089fd2a195f041762fffb7"
        },
        {
          "url": "https://github.com/grpc/grpc-go/commit/8668b69c167df908b6b3666dcbf40992b9e932a4"
        },
        {
          "url": "https://github.com/grpc/grpc-go/commit/93e31b48545e2a8aaeb6e06b47fb249f94e6297f"
        },
        {
          "url": "https://github.com/grpc/grpc-go/issues/9354"
        },
        {
          "url": "https://github.com/grpc/grpc-go/pull/9365"
        },
        {
          "url": "https://github.com/grpc/grpc-go/pull/9366"
        },
        {
          "url": "https://github.com/grpc/grpc-go/pull/9367"
        },
        {
          "url": "https://github.com/grpc/grpc-go/releases/tag/v1.82.2"
        },
        {
          "url": "https://github.com/grpc/grpc-go/releases/tag/v1.83.2"
        },
        {
          "url": "https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84445"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-84445"
        }
      ],
      "published": "2026-09-14T17:17:51+00:00",
      "updated": "2026-09-25T14:10:13+00:00",
      "affects": [
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.82.1",
          "versions": [
            {
              "version": "v1.82.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.82.1",
          "versions": [
            {
              "version": "v1.82.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.82.1",
          "versions": [
            {
              "version": "v1.82.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.82.1",
          "versions": [
            {
              "version": "v1.82.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.82.1",
          "versions": [
            {
              "version": "v1.82.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/google.golang.org/grpc@v1.82.1",
          "versions": [
            {
              "version": "v1.82.1",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/google.golang.org/grpc@v1.82.1"
        }
      ]
    },
    {
      "id": "GO-2026-5932",
      "source": {
        "name": "govulndb",
        "url": "https://pkg.go.dev/vuln/"
      },
      "ratings": [],
      "description": "The golang.org/x/crypto/openpgp package is unsafe by design, has numerous known security issues, is not maintained, and should not be used.\n\nIf you are required to interoperate with OpenPGP systems and need a maintained package, consider github.com/ProtonMail/go-crypto/openpgp which is a maintained fork that aims to be a drop-in replacement for this package.",
      "advisories": [
        {
          "url": "https://go.dev/issue/44226"
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5932"
        }
      ],
      "affects": [
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.54.0",
          "versions": [
            {
              "version": "v0.54.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.54.0",
          "versions": [
            {
              "version": "v0.54.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.54.0",
          "versions": [
            {
              "version": "v0.54.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.54.0",
          "versions": [
            {
              "version": "v0.54.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.54.0",
          "versions": [
            {
              "version": "v0.54.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "pkg:golang/golang.org/x/crypto@v0.54.0",
          "versions": [
            {
              "version": "v0.54.0",
              "status": "affected"
            }
          ]
        },
        {
          "ref": "urn:cdx:8fcc5713-f8ac-48e3-bc68-6ca1bb64c3d6/1#pkg:golang/golang.org/x/crypto@v0.54.0"
        }
      ]
    }
  ]
}